peter bassill · operator
$ cve CVE-2025-66039 JSON

CVE-2025-66039

9.8
CRITICAL · CVSS 3.1 · EPSS 3.3% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.28% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2025-12-09
Last modified2026-09-25

Affected (1)

VendorProduct
sangomafreepbx

References

→ the Explorer  ·  watch your stack  ·  NVD