CVE-2025-26377 | Nozomi Q-Free MaxTime up to 2.11.0 HTTP routes.lua authorization
A vulnerability marked as problematic has been reported in Nozomi Q-Free MaxTime up to 2.11.0. Affected by this vulnerability is an unknown functionality of the file maxprofile/users/routes.lua of the component HTTP Handler. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2025-26377. The attack is possible to be carried out remotely. No exploit exists.