Exploit discussion active in current signal (2 latest mentions)
Immediate actions
Prioritize remediation for affected systems immediately
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Track advisory updates for patch or workaround availability
Recommended action window: High priority (within 72h)
NVD description
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom extension configuration functionality areas. Authentication with a known username is required to exploit these vulnerabilities. Successful exploitation allows authenticated users to execute arbitrary SQL queries against the database, potentially enabling access to sensitive data or modification of database contents. This issue has been patched in version 16.0.92 for FreePBX 16 and version 17.0.6 for FreePBX 17.
The text announces three critical FreePBX vulnerabilities (CVE-2025-66039 and CVE-2025-61675) without providing technical details or remediation guidance.
#FreePBX is a popular open-source IP PBX management tool. @FreePBX manages #VoIP communications & requires high availability & relatively open access, making it a very attractive target for threat actors. It now has serious CVE vulns. HT @PicusSecurity https://cybersec.picussecurity.com/s/critical-freepbx-vulnerabilities-cve-2025-66039-cve-2025-61675-cve-2025-61675-25485
Post summary
The tweet alerts that FreePBX has serious CVEs but offers no technical or remedial details.
🚨 New Metasploit Modules Weaponize Critical FreePBX, Cacti, and SmarterMail Flaws (Unauth RCE + Persistence)
Metasploit 6.4.111 added seven modules chaining FreePBX auth bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) for unauth RCE, plus unauth RCE in Cacti <1.2.29 (CVE-2025-24367) and SmarterMail path traversal/file upload (CVE-2025-52691), alongside new persistence modules (Burp extension + SSH key injection). This matters because exploitation is now “push-button,” making rapid patching/segmentation and exposure validation urgent for internet-facing VoIP, monitoring, and mail servers.
🎯 Target: Global/Enterprise IT
#️⃣ Category: #Vulnerability#BlueTeam
🔗 URL: https://cyberpress.org/metasploit-modules-target-freepbx-cacti-smartermail/
Post summary
The article announces new Metasploit modules enabling rapid, push‑button exploitation of critical FreePBX, Cacti, and SmarterMail flaws, highlighting urgent patching and segmentation.
🚨 Metasploit Adds 7 Fresh Exploit Modules Targeting FreePBX, Cacti, and SmarterMail (Unauth RCE Chains)
This Metasploit update ships new modules chaining FreePBX auth-bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) to reach unauth RCE, plus unauth RCE for Cacti <1.2.29 (CVE-2025-24367) and SmarterMail file upload/path traversal (CVE-2025-52691) to drop webshells/cron-based persistence. This matters because defenders can immediately validate exposure and prioritize patching/hardening for widely deployed VoIP, monitoring, and mail systems.
🎯 Target: Global/Enterprise IT
#️⃣ Category: #Vulnerability#BlueTeam
🔗 URL: https://cybersecuritynews.com/metasploit-exploit-modules/
Post summary
Metasploit released seven new modules that chain multiple CVEs to achieve unauthenticated remote code execution on FreePBX, Cacti, and SmarterMail, enabling attackers to drop webshells or establish persistence.