FreePBX Endpoint Manager是FreePBX开源的一款集中管理IP电话终端配置模块。 FreePBX Endpoint Manager 16.0.92之前版本和17.0.6之前版本存在代码问题漏洞,该漏洞源于fwbrand参数存在经过身份验证的任意文件上传,可能导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FreePBX | endpointman | < 16.0.92 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-59051 | FreePBX Endpoint Manager command injection via Network Scanning feature | |
| CVE-2025-59429 | FreePBX core module vulnerable to reflected cross-site scripting via Asterisk HTTP Status | |
| CVE-2025-61675 | FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configurati |
No comments yet