CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> checksshconnect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
Other sources
Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> checksshconnect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sangoma FreePBX Endpoint Managerto a version that resolves this vulnerability.Fixed in 17.0.3 - Compensating control
If mitigations are unavailable, discontinue use of the affected product.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64328?
CVE-2025-64328 is considered a high-severity vulnerability due to its potential for post-authentication command injection.
How do I fix CVE-2025-64328?
To fix CVE-2025-64328, upgrade FreePBX Endpoint Manager to version 17.0.3 or later.
What type of attack does CVE-2025-64328 allow?
CVE-2025-64328 allows authenticated attackers to perform command injection attacks through the filestore module.
In which versions of FreePBX Endpoint Manager is CVE-2025-64328 found?
CVE-2025-64328 affects FreePBX Endpoint Manager versions 17.0.2.36 through 17.0.2.xx, prior to 17.0.3.
Who is at risk from CVE-2025-64328?
Authenticated users of FreePBX Endpoint Manager versions affected by CVE-2025-64328 are at risk of exploitation.