FreePBX 是一款开源的 IP PBX 系统。在版本 16.0.39 和 17.0.7 之前,通过用户控制面板(UCP)进行身份验证的用户,可以利用特制的 HTTP 字符串,以 Web 服务器用户(通常是 asterisk)的身份在 PBX 上执行任意命令。访问 UCP 需要进行身份验证。值得注意的是,相较于管理员控制面板(ACP)通常仅限 FreePBX 高级管理员账户使用,UCP 的访问权限更常被赋予权限较低的用户。UCP 使用的某些 URL 参数存在 sanitization(净化/过滤)不足的问题,未能
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FreePBX | security-reporting | < 16.0.39 |
affected |
< 17.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FreePBX | security-reporting | < 16.0.39 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54675 | 8.7 HIGH | FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Modu |
| CVE-2026-75600 | 8.6 HIGH | FreePBX: Authenticated API generatedocs Host Command Injection |
| CVE-2026-54710 | 8.6 HIGH | FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclus |
| CVE-2026-54708 | 8.6 HIGH | Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module |
| CVE-2026-45562 | 7.7 HIGH | FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module |
No comments yet