Exploitation Summary
CVE-2019-19492 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 6 public exploits from researchers including Metasploit, Chocapikk, tucommenceapousser, including a Metasploit module exploits/multi/misc/freeswitch_event_socket_cmd_exec.
AI-analyzed exploit summary This Metasploit module exploits FreeSWITCH's event socket interface to execute system commands via the `system` API command. It supports multiple platforms and payload types, including in-memory and dropper-based execution.
Description
FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.
Exploits (6)
This Metasploit module exploits FreeSWITCH's event socket interface to execute system commands via the `system` API command. It supports multiple platforms and payload types, including in-memory and dropper-based execution.
This repository contains a functional exploit for CVE-2019-19492, targeting FreeSWITCH's mod_event_socket. The exploit authenticates with a default password and executes arbitrary commands via the API system interface.
This repository contains a functional exploit for CVE-2019-19492, targeting FreeSWITCH's Event Socket interface. The exploit authenticates with a default password and executes arbitrary commands via the 'api system' command, supporting both single-target and Shodan-based mass exploitation.
This repository contains a functional Python exploit for CVE-2019-19492, targeting FreeSWITCH's Event Socket interface. The exploit authenticates with a default password and executes arbitrary commands via the 'api system' command, supporting both single-target and Shodan-based mass exploitation.
This repository contains a functional exploit for CVE-2019-19492, targeting FreeSWITCH's mod_event_socket. The exploit authenticates with a default password and executes arbitrary commands via the API system interface.
This Metasploit module exploits a command execution vulnerability in FreeSWITCH's event socket interface by authenticating with a default password and using the `system` or `bg_system` API commands to execute arbitrary system commands. It supports multiple payload types and targets Unix, Linux, and Windows systems.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H