CVE-2025-61675
largeAuthenticated SQL Injection in FreePBX Endpoint Manager Module
CVE-2025-61675 is a SQL injection flaw (CWE-89) in the FreePBX Endpoint Manager module, which is used to provision and manage telephony endpoints. An attacker who already has a valid login must send crafted requests to multiple parameters in the basestation, model, firmware, and custom extension configuration areas, causing arbitrary SQL queries to run against the FreePBX database. Successful exploitation can expose sensitive database contents or modify records stored in the system. FreePBX 16 deployments running Endpoint Manager before 16.0.92 and FreePBX 17 deployments running it before 17.0.6 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but a 39% EPSS probability of exploitation within 30 days (98th percentile) indicates defenders should patch promptly.
What to do: Update the Endpoint Manager module to 16.0.92 on FreePBX 16 or 17.0.6 on FreePBX 17 via the Module Admin interface. Restrict access to the FreePBX administration interface to trusted networks or VPN users, since a known username is required to exploit this flaw. Given related advisories for FreePBX covering file-upload and AUTHTYPE bypass flaws enabling RCE, review and apply all outstanding FreePBX module and core updates.
| Sangoma (FreePBX) Endpoint Manager module for FreePBX 16 | All versions prior to 16.0.92 |
| Sangoma (FreePBX) Endpoint Manager module for FreePBX 17 | All versions prior to 17.0.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom extension configuration functionality areas. Authentication with a known username is required to exploit these vulnerabilities. Successful exploitation allows authenticated users to execute arbitrary SQL queries against the database, potentially enabling access to sensitive data or modification of database contents. This issue has been patched in version 16.0.92 for FreePBX 16 and version 17.0.6 for FreePBX 17.
- Weakness
- CWE-89
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X