0-Day Exploit Hits FreePBX Servers, Admins Warned to Cut Internet Access
ID: ebb04464-b18e-57bb-a002-1ea598252923
STIX ID: report--ebb04464-b18e-57bb-a002-1ea598252923
Feed Name: Cyber Press
**Executive summary:** A critical Aug 2025 zero-day in the FreePBX Endpoint Manager allows unauthenticated privilege escalation leading to remote code execution; active exploitation was observed beginning Aug 21 with erratic system behavior and unauthorized configuration changes, prompting a vendor advisory on Aug 26. The report provides emergency mitigations (block ports 80/443, isolate systems, VPN/VLAN segmentation), detection steps (scan web logs for POSTs to /admin/modules/endpoint, search for base64_decode in PHP files, check new cronjobs invoking curl), forensic collection guidance (collect_forensics_freepbx.sh), and remediation advice (apply the vendor hotfix or remove the module, rotate credentials, inspect for backdoors).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
