CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.5. It may be remotely exploitable.
CVE
CVE-2025-1102
Severity
MEDIUM
CVSS
5.5
EPSS
0.14%
Original NVD Description
A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to affect the device confidentiality, integrity, or availability via crafted URLs or HTTP requests.
Related CVEs
Other vulnerabilities affecting the same vendor(s)