Q Free maintains a focused product line centered on the MaxTime toll-collection and traffic-management platform, which operates across a modest but strategically important infrastructure footprint. Despite limited product breadth, the vendor's prominence in the landscape reflects the critical role toll and congestion-pricing systems play in transportation networks and the widespread deployment of these systems across municipalities and highway operators. The vendor's vulnerability disclosures do not show a durable concentration in particular weakness classes, and the profile reflects the operational-technology and embedded-systems context typical of transportation infrastructure. Defenders managing toll-collection or congestion-pricing deployments should treat updates from this vendor as operationally sensitive given the system's role in public infrastructure; current severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Q Free over time
Signals from CVEs in this vendor scope (43 CVEs).
43 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-26344CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote | Feb 12, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-26341CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote a | Feb 12, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-26361CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote atta | Feb 12, 2025 | 9.1 | 28 | NO | NO |
CVE-2025-1100CRITICAL A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker to execute arbitrary co | Feb 12, 2025 | 9.8 | 28 | NO | NO |
CVE-2025-26359CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote a | Feb 12, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-26347CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attac | Feb 12, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-26345CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attac | Feb 12, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-26342CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote a | Feb 12, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-26339CRITICAL A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an unauthenticated remote attacker | Feb 12, 2025 | 9.8 | 25 | NO | NO |
CVE-2025-26378HIGH A CWE-862 "Missing Authorization" in maxprofile/users/routes.lua in Q-Free MaxTime less than or equal to version 2.11.0 allows an authenticated (low-privileged) attacker to reset p | Feb 12, 2025 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (43 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Q Free.
Media articles that mention a CVE ID that affects a product developed by Q Free — matched by CVE ID, not by vendor name.