FreePBX Endpoint Manager Authenticated OS Command Injection Vulnerability

Vulnerability

A vulnerability in the FreePBX Endpoint Manager module's Network Scanning feature allows authenticated users to execute operating system commands as the asterisk user. This issue arises from insufficient input sanitization of user-supplied data, enabling command injection through the web-based interface that integrates nmap functionality for network device discovery. The vulnerability affects Endpoint Manager versions 16 prior to 16.0.92 and 17 prior to 17.0.6.

Impact

Exploitation of this vulnerability allows for authenticated operating system command execution as the asterisk user.

Remediation

Users can update to FreePBX Endpoint Manager version 16.0.92 or 17.0.6 to address this vulnerability. It is also recommended to protect the FreePBX Admin Control Panel (ACP) from suspicious users, remove users who should not have access, and firewall the FreePBX ACP HTTP, HTTPS, and GraphQL ports.

Added: Oct 15, 2025, 12:17 AM
Updated: Oct 15, 2025, 12:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.8
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.