Impact
From 17.0.1 to 17.0.7 the FreePBX Music on Hold module permits dangerous command‑line options for /usr/bin/mpg123 and other allowed players. An authenticated administrator can supply options that write files, open control channels, or create Asterisk call files because the validation function does not reject them, allowing arbitrary command execution as the asterisk service user. The consequence is complete loss of confidentiality, integrity, and availability for the affected system, with the attacker able to execute any command at the privilege level of the asterisk daemon.
Affected Systems
The affected product is the FreePBX Music on Hold module. Systems running FreePBX versions 17.0.1 through 17.0.7 are impacted. The vulnerability is fixed starting with version 17.0.7.
Risk and Exploitability
The CVSS score of 7.6 indicates high severity. No EPSS score is available, but the absence of a KEV listing suggests no confirmed exploitation yet. The likely attack vector is an attacker who has authenticated administrator access to the FreePBX web interface, from which they can craft malicious input to the module. Since the vulnerability allows command execution of a privileged service account, the impact is severe.
OpenCVE Enrichment