FreePBX Vulnerabilities and Affected Products
Vulnerabilities associated with endpoint.
Products
Clear product- security-reporting9 vulnerabilities
- framework5 vulnerabilities
- endpoint4 vulnerabilities
- api3 vulnerabilities
- endpointman2 vulnerabilities
- FreePBX2 vulnerabilities
- tts2 vulnerabilities
- arimanager1 vulnerability
- backup1 vulnerability
- cdr1 vulnerability
- contactmanager1 vulnerability
- core1 vulnerability
- endpoint_manager1 vulnerability
- filestore1 vulnerability
- FreePBX Framework1 vulnerability
- missedcall1 vulnerability
- music1 vulnerability
- restapps1 vulnerability
- ucp1 vulnerability
- voicemail1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-67513MEDIUM | FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST APIFreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10. CWE-521Dec 10, 2025 | CVSS6.9v4.0 | EPSS0.264% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61675HIGH | FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parametersFreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom extension configuration functionality areas. Authentication with a known username is required to exploit these vulnerabilities. Successful exploitation allows aut… CWE-89Oct 14, 2025 | CVSS8.6v4.0 | EPSS39% | PoCs5 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-59051HIGH | FreePBX Endpoint Manager command injection via Network Scanning featureThe FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk user. Authentication with a known username is required. Updating to Endpoint Manager 16.0.92 or 17.0.6 addresses the issue. CWE-78Oct 14, 2025 | CVSS8.6v4.0 | EPSS0.641% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-57819CRITICAL | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCEFreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3. | CVSS10.0v4.0 | EPSS88.3% | PoCs23 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |