FreePBX 是一款开源的 IP PBX(IP 电话系统)软件。在 17.0.9 版本之前,经过身份验证并被授权访问 FreePBX 的 GraphQL API 模块接口的用户,可以执行任意 Shell 命令。要利用此漏洞,必须首先通过 API 模块的身份验证。 该漏洞源于 PBX API 模块中的文档生成器接受一个经过身份验证的主机(host)参数,并将其直接用于构建 Shell 命令。虽然代码路径在执行前会验证生成的 OAuth 访问令牌,但并未对主机参数进行验证或转义处理。这导致攻击者在通过身份验证后,可以
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FreePBX | security-reporting | < 17.0.9 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FreePBX | security-reporting | < 17.0.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54675 | 8.7 HIGH | FreePBX: Authenticated Remote Code Execution via File Upload and Convert in Soundlang Modu |
| CVE-2026-54710 | 8.6 HIGH | FreePBX: Authenticated Superfecta Arbitrary PHP Code Execution (RCE via Unsafe File Inclus |
| CVE-2026-54708 | 8.6 HIGH | Authenticated Remote Code Execution via Path Traversal in FreePBX Backup Module |
| CVE-2026-54674 | 8.6 HIGH | Authenticated Command Injection in FreePBX UCP Interface |
| CVE-2026-45562 | 7.7 HIGH | FreePBX: Authenticated Remote Code Execution in FreePBX Music on Hold (MoH) Module |
No comments yet