FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freepbx
Freepbx freepbx |
|
| Vendors & Products |
Freepbx
Freepbx freepbx |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access. | |
| Title | FreePBX 16 Authenticated Remote Code Execution via API Module | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-11T21:36:11.213Z
Updated: 2025-12-11T21:36:11.213Z
Reserved: 2025-12-11T00:58:28.456Z
Link: CVE-2024-58294
No data.
Status : Undergoing Analysis
Published: 2025-12-11T22:15:50.423
Modified: 2025-12-12T15:17:31.973
Link: CVE-2024-58294
No data.