CVE-2025-55211: FreePBX Post-Authenticated Command Injection
FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55211?
CVE-2025-55211 is rated as a critical vulnerability due to its potential to allow authenticated users to execute arbitrary shell commands.
How do I fix CVE-2025-55211?
To fix CVE-2025-55211, update to FreePBX version 17.0.21 or later as it contains the necessary patch.
Who is affected by CVE-2025-55211?
CVE-2025-55211 affects users of FreePBX versions from 17.0.19.11 to before 17.0.21.
What type of attack does CVE-2025-55211 allow?
CVE-2025-55211 allows authenticated users to perform remote code execution by altering language settings.
When was CVE-2025-55211 discovered?
CVE-2025-55211 was disclosed on a date prior to the release of FreePBX version 17.0.21.