ZeroHour

CVE-2025-61675

large

Authenticated SQL Injection in FreePBX Endpoint Manager Module

CVSS 4.0
8.6 high
EPSS
39%p98
Published
()
Modified
AI analysis

CVE-2025-61675 is a SQL injection flaw (CWE-89) in the FreePBX Endpoint Manager module, which is used to provision and manage telephony endpoints. An attacker who already has a valid login must send crafted requests to multiple parameters in the basestation, model, firmware, and custom extension configuration areas, causing arbitrary SQL queries to run against the FreePBX database. Successful exploitation can expose sensitive database contents or modify records stored in the system. FreePBX 16 deployments running Endpoint Manager before 16.0.92 and FreePBX 17 deployments running it before 17.0.6 are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but a 39% EPSS probability of exploitation within 30 days (98th percentile) indicates defenders should patch promptly.

What to do: Update the Endpoint Manager module to 16.0.92 on FreePBX 16 or 17.0.6 on FreePBX 17 via the Module Admin interface. Restrict access to the FreePBX administration interface to trusted networks or VPN users, since a known username is required to exploit this flaw. Given related advisories for FreePBX covering file-upload and AUTHTYPE bypass flaws enabling RCE, review and apply all outstanding FreePBX module and core updates.

Affected
Sangoma (FreePBX) Endpoint Manager module for FreePBX 16All versions prior to 16.0.92
Sangoma (FreePBX) Endpoint Manager module for FreePBX 17All versions prior to 17.0.6
Estimated exposure
large≈ tens of thousands of PBX deployments (order of magnitude 10k–100k systems with the module installed) — FreePBX is one of the most widely deployed open-source IP PBX platforms and Endpoint Manager is a commonly used provisioning module, but only FreePBX 16/17 installs with the module present are in scope and exploitation requires a valid…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom extension configuration functionality areas. Authentication with a known username is required to exploit these vulnerabilities. Successful exploitation allows authenticated users to execute arbitrary SQL queries against the database, potentially enabling access to sensitive data or modification of database contents. This issue has been patched in version 16.0.92 for FreePBX 16 and version 17.0.6 for FreePBX 17.

Weakness
CWE-89
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news