Exploit catalog results

Showing 1 PoC on this page

Metasploit

FreePBX filestore authenticated command injection

Metasploit exploitby Valentin Lobstein <chocapikk@leakix.net>Added to Metasploit 2026-03-11
ExploitCVE-2025-643281 file

exploit_unix/http/freepbx_filestore_cmd_injection · Ruby

Analysisdeepseek-v4-pro:cloud ·

Technical assessment

Metasploit module that exploits CVE-2025-64328, an authenticated command injection in FreePBX filestore module. It authenticates, checks the filestore version, and sends a crafted POST request with a command substitution payload in the 'key' parameter to execute arbitrary OS commands.

Backdoor review

No backdoor observed in reviewed code

The reviewed Metasploit module source code implements a standard authenticated command injection exploit for CVE-2025-64328. It sends a crafted POST request with a command substitution payload to the vulnerable FreePBX filestore endpoint. No concealed backdoor, deceptive payload, or operator-directed harm was observed in the provided text.

ClassificationExploit
Model confidence100%
AuthenticationRequired
Languagesruby
Target softwareFreePBX filestore
Attack typescommand injection
Evidence & reasoningClassification basis · observed behavior · safety review
Technical evidence

Classification basis and observed behavior

Classification basis

The module is a complete Metasploit exploit that includes authentication, version checking, and a command injection mechanism to execute arbitrary payloads on the target. It is classified as 'exploit' because its primary purpose is to gain remote code execution, not merely detect the vulnerability.

modules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:6modules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:113-121modules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:158-181

Requirements

  • Valid FreePBX credentials for a user in the 'Filestore' groupmodules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:36-38
  • Target running vulnerable filestore module version (>= 17.0.2.36, < 17.0.3)modules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:35-36

Observed behavior

  • Authenticates to FreePBX using provided username and passwordmodules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:123-132
  • Checks if target is vulnerable by retrieving and comparing filestore module versionmodules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:88-111
  • Sends POST request to /admin/ajax.php with command injection payload in 'key' parameter using $(cmd) syntaxmodules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:158-181
  • Executes attacker-supplied payload (e.g., reverse shell) on the target systemmodules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:113-121
Safety-review evidence

Behaviors behind the backdoor verdict

Observables

Exploit Behavior
Payload withheldThis is the documented exploit mechanism for CVE-2025-64328.modules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:161-180
Payload Execution
Payload withheldThis is the standard Metasploit pattern for delivering the user-chosen payload.modules/exploits/unix/http/freepbx_filestore_cmd_injection.rb:113-116
Review boundaries

What the analysis did not establish

  • Analysis based on module source code and metadata only; framework mixins, libraries, and external payloads are not expanded.
  • No runtime execution or verification of the exploit was performed.
  • Only the module source code and metadata were reviewed; Metasploit framework mixins, libraries, and external payloads were not expanded or analyzed.
  • The review does not assess the safety or reliability of the module or its payloads.
Model interpretation

This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.