/Vulnerability Library

FreePBX >= 17.0.2.36 && < 17.0.3 - Authenticated Command Injection

CVE-2025-64328
Verified

Description

FreePBX Endpoint Manager 17.0.2.36 to < 17.0.3 contains a command injection caused by improper sanitization in filestore module's testconnection check_ssh_connect() function, letting authenticated users execute commands as asterisk user.

Severity

Critical

CVSS Score

8.6

Exploit Probability

85%

Affected Product

freepbx

Published Date

March 7, 2026

Template Author

_th3y

CVE-2025-64328.yaml
8.6Score

CVSS Metrics

CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVE ID:
cve-2025-64328

References

https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvwhttps://theyhack.me/CVE-2025-64328-FreePBX-Authenticated-Command-Injection/https://www.cisa.gov/news-events/alerts/2026/02/03/cisa-adds-four-known-exploited-vulnerabilities-catalog

Remediation Steps

Upgrade to version 17.0.3 or later.