FreePBX 是一款开源的 IP PBX 系统。在 16.0.10 和 17.0.5 版本之前,其声音语言上传与转换功能中存在一个关键漏洞,允许经过身份认证的攻击者执行任意文件写入操作,从而直接导致远程代码执行(RCE)。利用此漏洞需要提供已知的用户名进行身份认证。该漏洞的根源在于文件转换过程中路径净化不足,攻击者可借此实施路径穿越攻击,将恶意的 PHP 文件写入 Web 服务器的根目录。该问题已在 16.0.10 和 17.0.5 版本中得到修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FreePBX | security-reporting | < 16.0.10 |
affected |
< 17.0.5 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FreePBX | security-reporting | < 16.0.10 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-75600 | 8.6 HIGH | FreePBX: Authenticated API generatedocs Host Command Injection |
| CVE-2026-54710 | 8.6 HIGH | FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclus |
| CVE-2026-54708 | 8.6 HIGH | Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module |
| CVE-2026-54674 | 8.6 HIGH | Authenticated Command Injection in FreePBX UCP Interface |
| CVE-2026-45562 | 7.7 HIGH | FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module |
No comments yet