CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-66039

CVSS 9.3v4.0pub. 2025-12-09upd. 2026-02-02

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

🤖 AI Analysis
How it works

When FreePBX Endpoint Manager is configured with "webserver" authentication type, the identity verification mechanism does not validate the correctness of submitted credentials. An attacker only needs to append an Authorization header with any arbitrary value to an HTTP request — the system incorrectly associates the session with the target user, completely bypassing password verification. This is a classic CWE-287 (improper authentication) vulnerability resulting from the lack of actual validation of the authorization header value.

Impact

An unauthenticated remote attacker can gain unauthorized access to any FreePBX system user account, taking control of telephone device management (endpoints). This results in potential complete takeover of the telephone system configuration, data theft, and the ability to perform further actions in the infrastructure.

Mitigation & patch

The FreePBX Endpoint Manager module should be updated to version 16.0.44 or later (16.x branch) or 17.0.23 or later (17.x branch). As an interim workaround, consider changing the authentication type from "webserver" to another available mode and restricting network access to the FreePBX management panel.

Who is affected

FreePBX Endpoint Manager — vulnerable versions are those prior to 16.0.44 (16.x branch) and 17.0.23 (17.x branch), when the authentication type is configured as "webserver"

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sangoma Freepbx

    APP
    Sangoma
    < 16.0.4417.0.1 – 17.0.23 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2025-57819CRITICAL10.0⚠ KEVPL ✓same product

Krytyczna podatność RCE i SQL injection w Sangoma FreePBX (bez uwierzytelnienia)

CVE-2019-19006CRITICAL9.8⚠ KEVPL ✓same product

Obejście uwierzytelnienia administratora w Sangoma FreePBX

CVE-2026-46376CRITICAL9.3PL ✓same product

FreePBX UCP: dostęp bez uwierzytelnienia przez wbudowane dane logowania

CVE-2021-45461CRITICAL9.8PL ✓same product

RCE w FreePBX przez moduł Rest Phone Apps (restapps)

CVE-2020-10666CRITICAL9.8PL ✓same product

RCE w module restapps dla Sangoma FreePBX i PBXact