PT-2025-35106 · Freepbx · Freepbx
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 15.0.66
FreePBX versions prior to 16.0.89
FreePBX versions prior to 17.0.3
Description
FreePBX is an open-source web-based graphical user interface for IP telephony systems. A critical issue exists in the
endpoint module where insufficiently sanitized user-supplied data allows unauthenticated attackers to bypass authentication controls. This flaw can be chained with SQL injection—a technique where malicious SQL statements are inserted into entry fields for execution—to perform arbitrary database manipulation and achieve remote code execution with SYSTEM-level privileges. There are reports of this issue being actively exploited in the wild.Recommendations
Update FreePBX version 15 to 15.0.66 or later.
Update FreePBX version 16 to 16.0.89 or later.
Update FreePBX version 17 to 17.0.3 or later.
As a temporary mitigation, restrict access to the
endpoint module to minimize the risk of exploitation.Exploit
Fix
RCE
SQL injection
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freepbx