Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 24 Feb 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sangoma firestore
|
|
| CPEs | cpe:2.3:a:sangoma:firestore:*:*:*:*:*:freepbx:*:* | |
| Vendors & Products |
Sangoma freepbx
|
Sangoma firestore
|
Wed, 04 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sangoma
Sangoma freepbx |
|
| CPEs | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sangoma
Sangoma freepbx |
|
| Metrics |
cvssV3_1
|
Tue, 03 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
ssvc
|
Tue, 03 Feb 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Tue, 03 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 07 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 07 Nov 2025 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Freepbx
Freepbx endpoint Manager Freepbx filestore Freepbx freepbx |
|
| Vendors & Products |
Freepbx
Freepbx endpoint Manager Freepbx filestore Freepbx freepbx |
Fri, 07 Nov 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3. | |
| Title | FreePBX Administration GUI is Vulnerable to Authenticated Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-13T22:08:51.717Z
Reserved: 2025-10-30T17:40:52.028Z
Link: CVE-2025-64328
Updated: 2025-11-07T17:45:16.827Z
Status : Analyzed
Published: 2025-11-07T04:15:47.397
Modified: 2026-02-24T19:30:59.130
Link: CVE-2025-64328
No data.
OpenCVE Enrichment
Updated: 2025-11-07T10:53:32Z