CVE-2025-64328
EUVD-2025-3823207.11.2025, 04:15
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| sangoma | freepbx | 17.0.2.36 ≤ 𝑥 < 17.0.3 |
𝑥
= Vulnerable software versions
References