关键漏洞信息 漏洞标题 Authenticated Command Injection in Network Scanning feature of Endpoint Manager 影响版本 endpoint (FreePBX 16): < 16.0.92 endpoint (FreePBX 17): < 17.0.6 修复版本 endpoint (FreePBX 16): 16.0.92 endpoint (FreePBX 17): 17.0.6 漏洞描述 Summary: The Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. Insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk user. Authentication with a known username is required. 缓解措施 Update to the latest fixed version of the endpoint module. Protect your ACP from suspicious users. Remove users that should not have access. Firewall your FreePBX ACP HTTP/HTTPS/GraphQL ports. 评分 CVSS 4.0 Base vector string: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N Current CVSS v4.0 Base score: 8.6 (High) Current CVSS v4.0 more complete score: 6.1 (Medium) Alternative CVSS v4.1 score: 0.9 (Low) 其他信息 CVE ID: CVE-2025-59051 Weaknesses: CWE-78