CVE 9.3 CRITICAL

FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header_CVE-2025-66039

9.3 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

AI Analysis

Authentication bypass vulnerability in FreePBX Endpoint Manager when the authentication type is set to webserver, allowing unauthenticated logins to the administrator control panel via a forged Basic Auth header.

Basic Information

ID CVE-2025-66039
Source GitHub_M
Published Dec 9, 2025 at 21:32

Affected Product

Vendor FreePBX
Product security-reporting
Version < 16.0.44
Affected Versions FreePBX security-reporting < 16.0.44
FreePBX security-reporting >= 17.0.1, < 17.0.23

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor FreePBX
Product FreePBX Endpoint Manager
Version < 16.0.44, < 17.0.23

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.