Vulnerability Analysis
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
CVE-2025-64328
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
CISA KEV
Nuclei Template
CVSS Base Score
8.6
HIGH
Exploitability:-
Impact Score:-
Temporal Score:-
EPSS:84.42%
Threat Intelligence Signals
CISA KEV
YES
KEV Date Added
2026-02-03
Ransomware Use
Unknown
KEV Due Date
2026-02-24
VulnCheck In-the-Wild
No
Nuclei Template
YES
EPSS Score
84.417%
EPSS Percentile
99.7th pct
GHSA ID
—
GitHub Severity
—
SSVC Exploitation
—
SSVC Automatable
—
Vulnerability Class
—
Identity & Timeline
| Status | - |
| Assigning Authority | - |
| CVSS Version / Source | - |
| Reserved | - |
| Published | - |
| Patch Date (date_public) | - |
| Exploit DB Date | - |
| First GitHub PoC Date | - |
| Last Updated | - |
| Time to Patch (Days to fix) | - |
| Exploit Release Gap | - |
| PoC Release Gap | - |
| Exploit DB References | None identified |
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| No affected products specified. | ||
Social Buzz