FreePBX 是一款开源的 IP PBX(电话交换机)系统。在 16.0.4 和 17.0.6 版本之前,FreePBX 的“等待音乐”(Music on Hold,简称 MoH)模块存在一个严重的安全漏洞,允许经过身份验证的攻击者以 Asterisk 服务的权限执行任意系统命令。利用该漏洞的前提是攻击者需拥有现有的 FreePBX 管理员账户权限。 该漏洞的根本原因在于,MoH 模块接受一个 POST 参数,用于定义自定义的 Asterisk 应用程序,但该参数在被存入数据库时未经任何清洗或过滤处理。随后,这些
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FreePBX | security-reporting | < 16.0.4 |
affected |
< 17.0.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FreePBX | security-reporting | < 16.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54675 | 8.7 HIGH | FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Modu |
| CVE-2026-75600 | 8.6 HIGH | FreePBX: Authenticated API generatedocs Host Command Injection |
| CVE-2026-54710 | 8.6 HIGH | FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclus |
| CVE-2026-54708 | 8.6 HIGH | Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module |
| CVE-2026-54674 | 8.6 HIGH | Authenticated Command Injection in FreePBX UCP Interface |
No comments yet