PT-2025-37763 · Freepbx · Freepbx

S0Nnywt

·

Published

2025-09-15

·

Updated

2025-10-17

·

CVE-2025-55211

CVSS v3.1
8.8
VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreePBX versions 17.0.19.11 through 17.0.20
Description FreePBX is a web-based graphical user interface. Authenticated users of the Administrator Control Panel (ACP) can execute arbitrary shell commands by manipulating the framework module's language settings. This allows malicious actors to potentially compromise the system.
Recommendations Update to version 17.0.21 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-55211
GHSA-XG83-M6Q5-Q24H

Affected Products

Freepbx