Metasploit Releases 7 New Exploit Modules covering FreePBX, Cacti and SmarterMail
ID: aa15847f-27bc-525d-9134-1c1ad61fbbe0
STIX ID: report--aa15847f-27bc-525d-9134-1c1ad61fbbe0
Feed Name: cybersecurityNews.com
Metasploit's latest release introduces seven new modules that enable unauthenticated and chained attacks against widely used infrastructure: FreePBX (authentication bypass CVE-2025-66039 chained to SQLi CVE-2025-61675 or file upload CVE-2025-61678 to achieve RCE or admin creation), Cacti (unauthenticated RCE via CVE-2025-24367), and SmarterMail (unauthenticated file upload/path traversal CVE-2025-52691), along with persistence modules for Burp Suite and consolidated SSH key persistence; organizations should prioritize patching, hardening exposed services, and auditing for signs of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
