Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

FreePBX Filestore Command Injection Vulnerability in Endpoint Manager

Vulnerability

A post-authentication command injection vulnerability has been identified in the FreePBX Endpoint Manager's filestore module, specifically in versions 17.0.2.36 prior to 17.0.3. This vulnerability allows authenticated users to inject commands via the testconnection -> check_ssh_connect() function. Exploitation of this issue could lead to arbitrary command execution on the server, with the potential for remote access as the asterisk user.

Impact

Exploitation of this vulnerability allows authenticated users to execute arbitrary commands on the server, potentially leading to unauthorized access as the asterisk user.

Reproduction

To reproduce this vulnerability, an authenticated user must access the FreePBX Administration interface and navigate to the Endpoint Manager filestore module. From there, the user can initiate a connection test that exploits the command injection vulnerability by injecting malicious commands into the SSH connection check process.

Remediation

Users are advised to update the filestore module to version 17.0.3 or later. Additionally, access to the FreePBX Administration Control Panel should be restricted to authorized users only.

Added: Nov 7, 2025, 4:17 AM
Updated: Feb 3, 2026, 3:59 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.5
remediation
7.7
relevance
1.0
threat
9.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.