FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 11:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Freepbx
Freepbx freepbx |
|
Vendors & Products |
Freepbx
Freepbx freepbx |
Tue, 16 Sep 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 15 Sep 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21. | |
Title | FreePBX Post-Authenticated Command Injection | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-09-15T21:00:13.557Z
Updated: 2025-09-16T15:45:00.835Z
Reserved: 2025-08-08T21:55:07.966Z
Link: CVE-2025-55211

Updated: 2025-09-16T15:44:10.815Z

Status : Awaiting Analysis
Published: 2025-09-15T21:15:36.100
Modified: 2025-09-16T12:49:16.060
Link: CVE-2025-55211

No data.