Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-67722

Опубликовано: 16 дек. 2025
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script amportal. In the deprecated amportal utility, the lookup for the freepbx_engine file occurs in /etc/asterisk/ directories. Typically, these are configured by FreePBX as writable by the asterisk user and any members of the asterisk group. This means that a member of the asterisk group can add their own freepbx_engine file in /etc/asterisk/ and upon amportal executing, it would exec that file with root permissions (even though the file was created and placed by a non-root user). Version 16.0.45 and 17.0.24 contain a fix for the issue. Other mitigation strategies are also available. Confirm only trusted local OS system users are members of the asterisk group. Look for suspicious files in the /etc/asterisk/ directory (

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
Версия от 16.0 (включая) до 16.0.45 (исключая)
cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
Версия от 17.0 (включая) до 17.0.24 (исключая)

EPSS

Процентиль: 1%
0.00011
Низкий

7.8 High

CVSS3

Дефекты

CWE-426

EPSS

Процентиль: 1%
0.00011
Низкий

7.8 High

CVSS3

Дефекты

CWE-426