9.3
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Description
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.
AI Analysis
Authentication bypass vulnerability in FreePBX Endpoint Manager when the authentication type is set to webserver, allowing unauthenticated logins to the administrator control panel via a forged Basic Auth header.
Basic Information
ID
CVE-2025-66039
Source
GitHub_M
Published
Dec 9, 2025 at 21:32
Affected Product
Vendor
FreePBX
Product
security-reporting
Version
< 16.0.44
Affected Versions
FreePBX security-reporting < 16.0.44
FreePBX security-reporting >= 17.0.1, < 17.0.23
FreePBX security-reporting >= 17.0.1, < 17.0.23
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
FreePBX
Product
FreePBX Endpoint Manager
Version
< 16.0.44, < 17.0.23