FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.
Metrics
Affected Vendors & Products
References
History
Fri, 17 Oct 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Sangoma
Sangoma freepbx |
|
CPEs | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | |
Vendors & Products |
Sangoma
Sangoma freepbx |
|
Metrics |
cvssV3_1
|
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Freepbx
Freepbx freepbx |
|
Vendors & Products |
Freepbx
Freepbx freepbx |
Tue, 16 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 15 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21. | |
Title | FreePBX Post-Authenticated Command Injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-15T21:00:13.557Z
Updated: 2025-09-16T15:45:00.835Z
Reserved: 2025-08-08T21:55:07.966Z
Link: CVE-2025-55211

Updated: 2025-09-16T15:44:10.815Z

Status : Analyzed
Published: 2025-09-15T21:15:36.100
Modified: 2025-10-17T14:46:44.293
Link: CVE-2025-55211

No data.