CVE-2025-59056: FreePBX vulnerable to unauthenticated Denial of Service
FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most modules store their configuration. This vulnerability is fixed in 15.0.38, 16.0.41, and 17.0.21.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59056?
CVE-2025-59056 is classified as a high-severity vulnerability due to its potential impact on system integrity.
How do I fix CVE-2025-59056?
To fix CVE-2025-59056, update FreePBX to the latest version that addresses this vulnerability.
What versions of FreePBX are affected by CVE-2025-59056?
CVE-2025-59056 affects FreePBX versions 15.0.0 to 15.0.38, 16.0.0 to 16.0.41, and 17.0.0 to 17.0.21.
What type of attacks does CVE-2025-59056 enable?
CVE-2025-59056 enables attackers to trigger the uninstall function maliciously, leading to the loss of module database tables.
Is there a workaround for CVE-2025-59056 until I can update?
Currently, there are no documented workarounds for CVE-2025-59056, so updating to a secure version is essential.