CVE-2025-61678Exploit

LOWCVSS 8.6 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting the fwbrand parameter. The fwbrand parameter allows an attacker to change the file path. Combined, these issues can result in a webshell being uploaded. Authentication with a known username is required to exploit this vulnerability. Successful exploitation allows authenticated users to upload arbitrary files to attacker-controlled paths on the server, potentially leading to remote code execution. This issue has been patched in version 16.0.92 for FreePBX 16 and version 17.0.6 for FreePBX 17.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 2 signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-01-31: 2PoC Mentioned / Linked · 2026-01-31: 2Exploit Tool / Code · 2026-01-31: 2Technical Details · 2026-01-31: 201-31
Signal classification1 categories
Exploit
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 New Metasploit Modules Weaponize Critical FreePBX, Cacti, and SmarterMail Flaws (Unauth RCE + Persistence) Metasploit 6.4.111 added seven modules chaining FreePBX auth bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) for unauth RCE, plus unauth RCE in Cacti <1.2.29 (CVE-2025-24367) and SmarterMail path traversal/file upload (CVE-2025-52691), alongside new persistence modules (Burp extension + SSH key injection). This matters because exploitation is now “push-button,” making rapid patching/segmentation and exposure validation urgent for internet-facing VoIP, monitoring, and mail servers. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/metasploit-modules-target-freepbx-cacti-smartermail/

    Post summary

    New Metasploit modules provide immediate, push‑button exploitation against FreePBX, Cacti, and SmarterMail vulnerabilities, underscoring an uptick in available exploit code for the listed CVEs.

    0000095
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 Metasploit Adds 7 Fresh Exploit Modules Targeting FreePBX, Cacti, and SmarterMail (Unauth RCE Chains) This Metasploit update ships new modules chaining FreePBX auth-bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) to reach unauth RCE, plus unauth RCE for Cacti <1.2.29 (CVE-2025-24367) and SmarterMail file upload/path traversal (CVE-2025-52691) to drop webshells/cron-based persistence. This matters because defenders can immediately validate exposure and prioritize patching/hardening for widely deployed VoIP, monitoring, and mail systems. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/metasploit-exploit-modules/

    Post summary

    Metasploit has added 7 exploit modules that chain multiple CVEs to achieve unauthenticated RCEs in FreePBX, Cacti, and SmarterMail, enabling defenders to validate exposure and prioritize patching.

    0000081
    196 followersView on X

Explore more