CVE-2025-61675Exploit

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom extension configuration functionality areas. Authentication with a known username is required to exploit these vulnerabilities. Successful exploitation allows authenticated users to execute arbitrary SQL queries against the database, potentially enabling access to sensitive data or modification of database contents. This issue has been patched in version 16.0.92 for FreePBX 16 and version 17.0.6 for FreePBX 17.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-01-31); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-01-31: 2Mentions · 2026-02-20: 2PoC Mentioned / Linked · 2026-01-31: 2Exploit Tool / Code · 2026-01-31: 2Technical Details · 2026-01-31: 201-3102-20
Signal classification3 categories
Exploit
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-01-312
Exploit2
2026-02-202
Disclosure1General1
Full discourse4 posts
  • Audrey Renée Bentley@BentleyAudrey
    Disclosure

    https://cybersec.picussecurity.com/s/critical-freepbx-vulnerabilities-cve-2025-66039-cve-2025-61675-cve-2025-61675-25487/1 Critical FreePBX Vulnerabilities: CVE-2025-66039, CVE-2025-61675, CVE-2025-61675

    Post summary

    The text announces three critical FreePBX vulnerabilities (CVE-2025-66039 and CVE-2025-61675) without providing technical details or remediation guidance.

    15091569
    33.1K followersView on X
  • Ben Rothke@benrothke
    General

    #FreePBX is a popular open-source IP PBX management tool. @FreePBX manages #VoIP communications & requires high availability & relatively open access, making it a very attractive target for threat actors. It now has serious CVE vulns. HT @PicusSecurity https://cybersec.picussecurity.com/s/critical-freepbx-vulnerabilities-cve-2025-66039-cve-2025-61675-cve-2025-61675-25485

    Post summary

    The tweet alerts that FreePBX has serious CVEs but offers no technical or remedial details.

    0000068
    9.1K followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 New Metasploit Modules Weaponize Critical FreePBX, Cacti, and SmarterMail Flaws (Unauth RCE + Persistence) Metasploit 6.4.111 added seven modules chaining FreePBX auth bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) for unauth RCE, plus unauth RCE in Cacti <1.2.29 (CVE-2025-24367) and SmarterMail path traversal/file upload (CVE-2025-52691), alongside new persistence modules (Burp extension + SSH key injection). This matters because exploitation is now “push-button,” making rapid patching/segmentation and exposure validation urgent for internet-facing VoIP, monitoring, and mail servers. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/metasploit-modules-target-freepbx-cacti-smartermail/

    Post summary

    The article announces new Metasploit modules enabling rapid, push‑button exploitation of critical FreePBX, Cacti, and SmarterMail flaws, highlighting urgent patching and segmentation.

    0000095
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 Metasploit Adds 7 Fresh Exploit Modules Targeting FreePBX, Cacti, and SmarterMail (Unauth RCE Chains) This Metasploit update ships new modules chaining FreePBX auth-bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) to reach unauth RCE, plus unauth RCE for Cacti <1.2.29 (CVE-2025-24367) and SmarterMail file upload/path traversal (CVE-2025-52691) to drop webshells/cron-based persistence. This matters because defenders can immediately validate exposure and prioritize patching/hardening for widely deployed VoIP, monitoring, and mail systems. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/metasploit-exploit-modules/

    Post summary

    Metasploit released seven new modules that chain multiple CVEs to achieve unauthenticated remote code execution on FreePBX, Cacti, and SmarterMail, enabling attackers to drop webshells or establish persistence.

    0000081
    196 followersView on X

Explore more