FreePBX 是一款开源 IP 电话交换系统(IP PBX)。在 16.0.40 和 17.0.7 版本之前,其 superfecta 模块中存在一个关键远程代码执行(RCE)漏洞,该漏洞源于对任意 PHP 文件的不安全包含。攻击者只要拥有合法的认证凭据,即可利用此漏洞以 Web 服务器用户的权限在服务器上执行任意 PHP 代码。漏洞利用需要已知用户名的认证。 该漏洞的根本原因在于 Superfecta 模块的 AJAX 处理程序中“options”和“save_options”处理逻辑。相关代码会根据用户提供的
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FreePBX | security-reporting | < 16.0.40 |
affected |
< 17.0.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FreePBX | security-reporting | < 16.0.40 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54675 | 8.7 HIGH | FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Modu |
| CVE-2026-75600 | 8.6 HIGH | FreePBX: Authenticated API generatedocs Host Command Injection |
| CVE-2026-54708 | 8.6 HIGH | Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module |
| CVE-2026-54674 | 8.6 HIGH | Authenticated Command Injection in FreePBX UCP Interface |
| CVE-2026-45562 | 7.7 HIGH | FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module |
No comments yet