Showing 2 vulnerabilities on this page for FreePBX

Signals CISA KEV Ransomware Nuclei
FreePBX vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

FreePBX 16 Authenticated Remote Code Execution via API Module

FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.

CWE-78Dec 11, 2025
CVSS8.7v4.0EPSS3.62%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

freepbx FreePBX Improper Control of Generation of Code ('Code Injection')

htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserialize function, as exploited in the wild in September 2014.

CWE-94Oct 7, 2014
CVSS10.0v2.0EPSS43.3%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX