Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-55211


FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.


Published

2025-09-15T21:15:36.100

Last Modified

2025-10-17T14:46:44.293

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sangoma freepbx < 17.0.21 Yes

References