CVE-2025-64328

Confirmed PUBLISHED

FreePBX Administration GUI is Vulnerable to Authenticated Command Injection

FreePBX · filestore

1 day faster than CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
8.6 High EPSS 84.4%

At a Glance

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.

nuclei_scanner cisa
CVE Published
Nov 07, 2025
Exploitation Reported
Jun 01, 2026
CVSS
8.6 High
EPSS
84.4%
Remote Low complexity No user interaction

Affected Versions

Vendor Product Version Status
FreePBX
filestore

>= 17.0.2.36, < 17.0.3

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.