FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most modules store their configuration. This vulnerability is fixed in 15.0.38, 16.0.41, and 17.0.21.
History

Wed, 17 Sep 2025 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Freepbx
Freepbx freepbx
Vendors & Products Freepbx
Freepbx freepbx

Tue, 16 Sep 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 15 Sep 2025 21:15:00 +0000

Type Values Removed Values Added
Description FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most modules store their configuration. This vulnerability is fixed in 15.0.38, 16.0.41, and 17.0.21.
Title FreePBX vulnerable to unauthenticated Denial of Service
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/AU:Y/R:U/V:D/RE:L/U:Red'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-15T21:04:07.875Z

Updated: 2025-09-16T15:42:30.971Z

Reserved: 2025-09-08T16:19:26.173Z

Link: CVE-2025-59056

cve-icon Vulnrichment

Updated: 2025-09-16T15:42:26.809Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-15T21:15:36.470

Modified: 2025-09-16T12:49:16.060

Link: CVE-2025-59056

cve-icon Redhat

No data.