CVE-2025-1100

Severity CVSS v4.0:
Pending analysis
Type:
CWE-259 Use of Hard-coded Password
Publication date:
12/02/2025
Last modified:
24/10/2025

Description

A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary code with root privileges via SSH.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:q-free:maxtime:*:*:*:*:*:*:*:* 2.11.0 (including)