Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-30361 Sangoma FreePBX 1805 through 2203 on Linux contains hardcoded credentials for the Asterisk REST Interface (ARI), which allows remote attackers to reconfigure Asterisk and make external and internal calls via HTTP and WebSocket requests sent to the API.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-02-13T15:46:39.284Z

Reserved: 2023-02-26T00:00:00.000Z

Link: CVE-2023-26566

cve-icon Vulnrichment

Updated: 2024-08-02T11:53:54.046Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-05-14T12:39:11.817

Modified: 2024-11-21T07:51:45.787

Link: CVE-2023-26566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-13T11:15:00Z