216.73.217.22

CVE-2025-64328

· Published 07/11/2025 05:15 · Modified 18/06/2026 17:18 · Author: AlienVault

Labels: CVE-2025-64328 2025-11-07CVE-2025-64328CWE-78[email protected]

Essential information

Published
07/11/2025 05:15
Modified
18/06/2026 17:18
Author
AlienVault
Creator
AlienVault
CVSS
7.2 HIGH (v3.1) 8.6 HIGH (v4.0)
CISA KEV
Yes
CWE
CWE-78
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
[email protected]
NVD
View on NVD

References