FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command Injection
CVE-2025-64328
Verified
Description
FreePBX Endpoint Manager 17.0.2.36 to < 17.0.3 contains a command injection caused by improper sanitization in filestore module's testconnection check_ssh_connect() function, letting authenticated users execute commands as asterisk user.
Severity
Critical
CVSS Score
8.6
Exploit Probability
85%
Affected Product
freepbx
Published Date
March 7, 2026
Template Author
_th3y
CVE-2025-64328.yaml
8.6Score
CVSS Metrics
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE ID:
cve-2025-64328
Remediation Steps
Upgrade to version 17.0.3 or later.