FreePBX RCE Vulnerabilities Threaten Telecom Servers
ID: 6bac3bc8-1fe8-5abe-aa99-02a2948a64ec
STIX ID: report--6bac3bc8-1fe8-5abe-aa99-02a2948a64ec
Feed Name: securityonline.info
Threat Score
FreePBX disclosure: two critical authenticated vulnerabilities (CVSS 8.6) affecting the Superfecta module (arbitrary PHP inclusion leading to RCE) and the UCP interface (authenticated command injection) can allow attackers to execute code as the web server and fully compromise VoIP hosts; administrators are advised to apply provided patches and restrict access to ACP/UCP immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
