FreePBX 是一款开源的 IP PBX(互联网协议电话交换机)系统。在版本 16.0.72 和 17.0.7 之前,FreePBX 的备份模块中存在一个关键漏洞,允许经过身份验证的攻击者在服务器上执行任意代码。该漏洞利用的前提是攻击者拥有已知的、具备足够访问权限(或对备份文件具有写入权限)的用户名凭据。此漏洞的根本原因是在备份恢复功能中存在不恰当的路径净化(path sanitization)处理,导致攻击者能够将恶意的 PHP 文件上传至网站的根目录。该问题已在版本 16.0.72 和 17.0.7 中修复。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FreePBX | security-reporting | < 16.0.72 |
affected |
< 17.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FreePBX | security-reporting | < 16.0.72 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54675 | 8.7 HIGH | FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Modu |
| CVE-2026-75600 | 8.6 HIGH | FreePBX: Authenticated API generatedocs Host Command Injection |
| CVE-2026-54710 | 8.6 HIGH | FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclus |
| CVE-2026-54674 | 8.6 HIGH | Authenticated Command Injection in FreePBX UCP Interface |
| CVE-2026-45562 | 7.7 HIGH | FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module |
No comments yet