CVE-2025-26355 | Nozomi Q-Free MaxTime up to 2.11.0 HTTP database.lua path traversal
A vulnerability has been found in Nozomi Q-Free MaxTime up to 2.11.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file maxtime/api/database/database.lua of the component HTTP Handler. The manipulation leads to path traversal: '.../...//'.
This vulnerability is known as CVE-2025-26355. The attack can be launched remotely. There is no exploit available.