logo

0-Day Exploit Hits FreePBX Servers, Admins Warned to Cut Internet Access

ID: ebb04464-b18e-57bb-a002-1ea598252923

STIX ID: report--ebb04464-b18e-57bb-a002-1ea598252923

Feed Name: Cyber Press

Threat Score
90/100

Date Published: 2025-08-28

Date Updated: 2026-04-19

Author: AnuPriya

...
...

**Executive summary:** A critical Aug 2025 zero-day in the FreePBX Endpoint Manager allows unauthenticated privilege escalation leading to remote code execution; active exploitation was observed beginning Aug 21 with erratic system behavior and unauthorized configuration changes, prompting a vendor advisory on Aug 26. The report provides emergency mitigations (block ports 80/443, isolate systems, VPN/VLAN segmentation), detection steps (scan web logs for POSTs to /admin/modules/endpoint, search for base64_decode in PHP files, check new cronjobs invoking curl), forensic collection guidance (collect_forensics_freepbx.sh), and remediation advice (apply the vendor hotfix or remove the module, rotate credentials, inspect for backdoors).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.