FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.
When FreePBX Endpoint Manager is configured with "webserver" authentication type, the identity verification mechanism does not validate the correctness of submitted credentials. An attacker only needs to append an Authorization header with any arbitrary value to an HTTP request — the system incorrectly associates the session with the target user, completely bypassing password verification. This is a classic CWE-287 (improper authentication) vulnerability resulting from the lack of actual validation of the authorization header value.
An unauthenticated remote attacker can gain unauthorized access to any FreePBX system user account, taking control of telephone device management (endpoints). This results in potential complete takeover of the telephone system configuration, data theft, and the ability to perform further actions in the infrastructure.
The FreePBX Endpoint Manager module should be updated to version 16.0.44 or later (16.x branch) or 17.0.23 or later (17.x branch). As an interim workaround, consider changing the authentication type from "webserver" to another available mode and restricting network access to the FreePBX management panel.
FreePBX Endpoint Manager — vulnerable versions are those prior to 16.0.44 (16.x branch) and 17.0.23 (17.x branch), when the authentication type is configured as "webserver"
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSangoma Freepbx
APPSangoma< 16.0.4417.0.1 – 17.0.23 (excl.)
Related vulnerabilities
Krytyczna podatność RCE i SQL injection w Sangoma FreePBX (bez uwierzytelnienia)
Obejście uwierzytelnienia administratora w Sangoma FreePBX
FreePBX UCP: dostęp bez uwierzytelnienia przez wbudowane dane logowania
RCE w FreePBX przez moduł Rest Phone Apps (restapps)
RCE w module restapps dla Sangoma FreePBX i PBXact