CVE-2025-59051: FreePBX Endpoint Manager command injection via Network Scanning feature
The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk user. Authentication with a known username is required. Updating to Endpoint Manager 16.0.92 or 17.0.6 addresses the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59051?
CVE-2025-59051 has a high severity due to insufficient input sanitization that can lead to OS command injection risks.
How do I fix CVE-2025-59051?
To fix CVE-2025-59051, upgrade the FreePBX Endpoint Manager to version 16.0.92 or later, or 17.0.6 or later.
Which versions of FreePBX Endpoint Manager are affected by CVE-2025-59051?
FreePBX Endpoint Manager versions prior to 16.0.92 and 17.0.6 are affected by CVE-2025-59051.
What impact does CVE-2025-59051 have on my system?
CVE-2025-59051 may allow authenticated users to execute arbitrary OS commands, potentially compromising system security.
Is there a workaround for CVE-2025-59051 if I cannot immediately update?
Currently, there are no documented workarounds for CVE-2025-59051 aside from applying the necessary updates.