Record summary

CVE-2025-55211 has a selected CVSS score of 6.3 (medium).

Description

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 16, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List>= 17.0.19.11, < 17.0.21affected

References

1