FreePBX Vulnerabilities Enable Remote Code Execution via Authentication Bypass
First seen 16 Dec 2025, 19:56 UTC
•
•97% similarity
•63
Share:
Export
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Browse articles
FreePBX has addressed critical vulnerabilities in its Endpoint Manager module that allow for authentication bypass and remote code execution. Discovered by Horizon3.ai researchers, these vulnerabilities affect telephony endpoint configurations in the open-source IP PBX system and include three high-severity issues distinct from CVE-2025-57819. CVE-2025-66039 is one of the identified vulnerabilities that enables this exploit.
ThreatCluster AI