FreePBX Endpoint Manager是FreePBX开源的一款集中管理IP电话终端配置模块。 FreePBX Endpoint Manager 16.0.92之前版本和17.0.6之前版本存在SQL注入漏洞,该漏洞源于basestation、model、firmware和custom extension配置功能区域存在多个参数存在SQL注入漏洞,可能导致执行任意SQL查询。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Detection for CVE-2025-61675, CVE-2025-61678 & CVE-2025-66039 | https://github.com/rxerium/FreePBX-Vulns-December-25 | POC Details |
| 2 | 🔍 Detect critical FreePBX vulnerabilities with Nuclei templates for CVE-2025-61675, CVE-2025-61678, and CVE-2025-66039 to strengthen your system's security. | https://github.com/jhow019/FreePBX-Vulns-December-25 | POC Details |
| 3 | 🔍 Detect critical vulnerabilities in FreePBX with Nuclei templates for CVE-2025-61675, CVE-2025-61678, and CVE-2025-66039. Protect your system now. | https://github.com/jhow019/jhow019.github.io | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-59051 | FreePBX Endpoint Manager command injection via Network Scanning feature | |
| CVE-2025-59429 | FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status | |
| CVE-2025-61678 | FreePBX Endpoint Manager vulnerable to authenticated arbitrary file upload via fwbrand par |
No comments yet