Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-108161— FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download

Quick assessment

Affected
fusionpbx fusionpbx
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FusionPBX 5.6.5 及之前版本在 函数中存在操作系统命令注入漏洞。攻击者无需身份验证即可通过拨打带有恶意主叫标识符(Caller ID)的呼叫,实现命令执行。当启用 文件名模板时,攻击者可在主叫方名称或号码中嵌入 shell 元字符(例如 )。一旦特权用户下载多个录音文件并打包为 ZIP 格式,这些命令将以 Web 服务器用户的身份被执行。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
fusionpbx fusionpbx ≤ 5.6.5 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-108161

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FusionPBX through 5.6.5 OS Command Injection via Caller ID in Recording ZIP Download
Source: CVE Program / CVE List V5
Vulnerability Description
FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
fusionpbx fusionpbx 0 ~ 5.6.5 -

II. Public POCs for CVE-2026-108161

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-108161

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-108161 (2)

Vendor Advisories for CVE-2026-108161 (1)

Vendor Pages for CVE-2026-108161 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-108161

No comments yet


Leave a comment