Critical FreePBX Flaws Let Unauthenticated Attackers Execute Commands and Hijack Admin Accounts
ID: 6171d5e2-ab2c-5f90-9020-16e8c14cfe8f
STIX ID: report--6171d5e2-ab2c-5f90-9020-16e8c14cfe8f
Feed Name: Cyber Press
Threat Score
Sangoma released fixes for two critical FreePBX vulnerabilities: an unauthenticated RCE in the UCP Node socket.io implementation and an SQL injection in the missedcall module that can be triggered via SIP Caller ID; both are rated CVSS 9.3 and can lead to full admin takeover on internet-facing FreePBX 16/17 systems, so administrators are urged to patch immediately and apply mitigations (Responsive Firewall, restrict inbound SIP, enable MFA/SAML, deploy SBCs).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
