CVE-2025-66039Exploit(sangoma / freepbx)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for sangoma freepbx systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freepbx

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 3 signals
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 4 signals
  • General: 3 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 2 mentions (2026-01-31); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
freepbx

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-01-31: 2Mentions · 2026-02-01: 1Mentions · 2026-02-20: 2Mentions · 2026-03-19: 1Mentions · 2026-04-01: 1PoC Mentioned / Linked · 2026-01-31: 2Exploit Tool / Code · 2026-01-31: 2Exploit Tool / Code · 2026-02-01: 1Technical Details · 2026-01-31: 2Technical Details · 2026-02-01: 1Technical Details · 2026-04-01: 101-3102-0102-2003-1904-01
Signal classification3 categories
Exploit
342.9%
General
342.9%
Disclosure
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-312
Exploit2
2026-02-011
Exploit1
2026-02-202
Disclosure1General1
2026-03-191
General1
2026-04-011
General1
Full discourse7 posts
  • Audrey Renée Bentley@BentleyAudrey
    General

    https://cybersec.picussecurity.com/s/critical-freepbx-vulnerabilities-cve-2025-66039-cve-2025-61675-cve-2025-61675-25487/1 Critical FreePBX Vulnerabilities: CVE-2025-66039, CVE-2025-61675, CVE-2025-61675

    Post summary

    The text merely lists three CVE identifiers for Critical FreePBX vulnerabilities, offering no additional information or context.

    15091569
    33.1K followersView on X
  • Florian Hansemann@CyberWarship
    General

    ''The FreePBX Rabbit Hole: CVE-2025-66039 & More'' #infosec #pentest #redteam #blueteam https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/

    Post summary

    The tweet merely announces a link to an article about FreePBX vulnerabilities, providing no concrete details or actionable information.

    010361.5K
    87.2K followersView on X
  • reverseame@reverseame
    General

    The FreePBX Rabbit Hole: CVE-2025-66039 and others #FreePBX #Vulnerabilities #CVE202566039 #RCE #SQLInjection https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/

    Post summary

    The tweet points to an article on multiple FreePBX vulnerabilities, including CVE-2025-66039 with RCE and SQL injection potential, but provides no details on exploitation, patches, or real‑world usage.

    01011711
    21.8K followersView on X
  • Hacker Affairs@hackeraffairs
    Exploit

    🛠️ Metasploit Update Adds 7 New Modules for FreePBX Chains, Cacti and SmarterMail Metasploit Framework has published its January 30, 2026 weekly wrap up, adding seven new modules alongside a set of fixes. Three of the new modules target FreePBX by chaining CVE-2025-66039 with additional flaws to reach remote code execution, while new exploit modules were added for Cacti and SmarterMail. The release also includes two persistence modules and multiple fixes affecting credential handling and scanner reporting. Read: https://hackeraffairs.com/metasploit-update-adds-7-new-modules-for-freepbx-chains-cacti-and-smartermail/

    Post summary

    Metasploit released new exploit modules targeting FreePBX (via CVE‑2025‑66039), Cacti, and SmarterMail, providing functional code but with no evidence of active exploitation in the wild.

    00010140
    32 followersView on X
  • Ben Rothke@benrothke
    Disclosure

    #FreePBX is a popular open-source IP PBX management tool. @FreePBX manages #VoIP communications & requires high availability & relatively open access, making it a very attractive target for threat actors. It now has serious CVE vulns. HT @PicusSecurity https://cybersec.picussecurity.com/s/critical-freepbx-vulnerabilities-cve-2025-66039-cve-2025-61675-cve-2025-61675-25485

    Post summary

    The tweet announces that FreePBX has been found to have serious CVE vulnerabilities, linking to a security blog for additional details.

    0000068
    9.1K followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 New Metasploit Modules Weaponize Critical FreePBX, Cacti, and SmarterMail Flaws (Unauth RCE + Persistence) Metasploit 6.4.111 added seven modules chaining FreePBX auth bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) for unauth RCE, plus unauth RCE in Cacti <1.2.29 (CVE-2025-24367) and SmarterMail path traversal/file upload (CVE-2025-52691), alongside new persistence modules (Burp extension + SSH key injection). This matters because exploitation is now “push-button,” making rapid patching/segmentation and exposure validation urgent for internet-facing VoIP, monitoring, and mail servers. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/metasploit-modules-target-freepbx-cacti-smartermail/

    Post summary

    The post announces newly available Metasploit modules that enable push‑button exploitation of several critical CVEs in FreePBX, Cacti, and SmarterMail, emphasizing functional exploit code but not claiming active attacks.

    0000095
    196 followersView on X
  • ThreatSynop@ThreatSynop
    Exploit

    🚨 Metasploit Adds 7 Fresh Exploit Modules Targeting FreePBX, Cacti, and SmarterMail (Unauth RCE Chains) This Metasploit update ships new modules chaining FreePBX auth-bypass (CVE-2025-66039) with SQLi (CVE-2025-61675) or unrestricted upload (CVE-2025-61678) to reach unauth RCE, plus unauth RCE for Cacti <1.2.29 (CVE-2025-24367) and SmarterMail file upload/path traversal (CVE-2025-52691) to drop webshells/cron-based persistence. This matters because defenders can immediately validate exposure and prioritize patching/hardening for widely deployed VoIP, monitoring, and mail systems. 🎯 Target: Global/Enterprise IT #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/metasploit-exploit-modules/

    Post summary

    Metasploit has released seven new modules chaining multiple CVEs to achieve unauthenticated RCE and persistence, enabling defenders to test exposure and prioritize patching.

    0000081
    196 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomafreepbx---

Explore more