EIP-2026-104727
PRE-CVEFreePBX < 13.0.188 - Remote Command Execution (Metasploit)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-104727. PoCs published by 0x4148.
AI-analyzed exploit summary This exploit targets FreePBX < 13.0.188 via insufficient input sanitization in the Hotelwakeup module, allowing unauthenticated remote command execution by manipulating the 'destination' and 'language' parameters to write malicious PHP code to a .call file, which is then executed by the server.
Description
FreePBX < 13.0.188 - Remote Command Execution (Metasploit)
Exploits (1)
This exploit targets FreePBX < 13.0.188 via insufficient input sanitization in the Hotelwakeup module, allowing unauthenticated remote command execution by manipulating the 'destination' and 'language' parameters to write malicious PHP code to a .call file, which is then executed by the server.