By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE
Tech News

FreePBX Patches Critical SQLi, File-Upload, and AUTHTYPE Bypass Flaws Enabling RCE

By Viral Trending Content 4 Min Read
Share
SHARE

Dec 15, 2025Ravie LakshmananVulnerability / Software Security

Multiple security vulnerabilities have been disclosed in the open-source private branch exchange (PBX) platform FreePBX, including a critical flaw that could result in an authentication bypass under certain configurations.

The shortcomings, discovered by Horizon3.ai and reported to the project maintainers on September 15, 2025, are listed below –

  • CVE-2025-61675 (CVSS score: 8.6) – Numerous authenticated SQL injection vulnerabilities impacting four unique endpoints (basestation, model, firmware, and custom extension) and 11 affected parameters that enable read and write access to the underlying SQL database
  • CVE-2025-61678 (CVSS score: 8.6) – An authenticated arbitrary file upload vulnerability that allows an attacker to exploit the firmware upload endpoint to upload a PHP web shell after obtaining a valid PHPSESSID and run arbitrary commands to leak the contents of sensitive files (e.g., “/etc/passwd”)
  • CVE-2025-66039 (CVSS score: 9.3) – An authentication bypass vulnerability that occurs when the “Authorization Type” (aka AUTHTYPE) is set to “webserver,” allowing an attacker to log in to the Administrator Control Panel via a forged Authorization header
Cybersecurity

It’s worth mentioning here that the authentication bypass is not vulnerable in the default configuration of FreePBX, given that the “Authorization Type” option is only displayed when the three following values in the Advanced Settings Details are set to “Yes”:

  • Display Friendly Name
  • Display Readonly Settings, and
  • Override Readonly Settings

However, once the prerequisite is met, an attacker could send crafted HTTP requests to sidestep authentication and insert a malicious user into the “ampusers” database table, effectively accomplishing something similar to CVE-2025-57819, another flaw in FreePBX that was disclosed as having been actively exploited in the wild in September 2025.

“These vulnerabilities are easily exploitable and enable authenticated/unauthenticated remote attackers to achieve remote code execution on vulnerable FreePBX instances,” Horizon3.ai security researcher Noah King said in a report published last week.

The issues have been addressed in the following versions –

  • CVE-2025-61675 and CVE-2025-61678 – 16.0.92 and 17.0.6 (Fixed on October 14, 2025)
  • CVE-2025-66039 – 16.0.44 and 17.0.23 (Fixed on December 9, 2025)

In addition, the option to choose an authentication provider has now been removed from Advanced Settings and requires users to set it manually through the command-line using fwconsole. As temporary mitigations, FreePBX has recommended that users set “Authorization Type” to “usermanager,” set “Override Readonly Settings” to “No,” apply the new configuration, and reboot the system to disconnect any rogue sessions.

Cybersecurity

“If you did find that web server AUTHTYPE was enabled inadvertently, then you should fully analyze your system for signs of any potential compromise,” it said.

Users are also displayed a warning on the dashboard, stating “webserver” may offer reduced security compared to “usermanager.” For optimal protection, it’s advised to avoid using this authentication type.

“It’s important to note that the underlying vulnerable code is still present and relies on authentication layers in front to provide security and access to the FreePBX instance,” King said. “It still requires passing an Authorization header with a Basic base64 encoded username:password.”

“Depending on the endpoint, we noticed a valid username was required. In other cases, such as the file upload shared above, a valid username is not required, and you can achieve remote code execution with a few steps, as outlined. It is best practice not to use the authentication type webserver as it appears to be legacy code.”

You Might Also Like

What cyber defenders can learn from emergency healthcare

AI Safety Under Strain, As AI Companies Rush New Models

HPE warns of maximum severity RCE flaw in OneView software

iPhone 17e: Price, Release Date, Specs and Features

Pumped Hydro Energy Storage Is Having a Renaissance

TAGGED: Authentication, Cyber Security, Cybersecurity, Internet, Open Source, Remote Code Execution, software security, SQL Injection, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article China’s economy loses momentum amid spending and investment slump
Next Article Esri launches interactive map of festive events across Ireland
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Jimmy Carr Tells UK To Mine Bitcoin With Wasted Night-Time Power
Crypto
What cyber defenders can learn from emergency healthcare
Tech News
AI Safety Under Strain, As AI Companies Rush New Models
Tech News
HPE warns of maximum severity RCE flaw in OneView software
Tech News
BoE delivers Christmas rate cut after cooler-than-expected inflation
Business
ADA could slip below $0.30 as bearish momentum builds
Crypto
Forget Mac Mini, Amazon’s 4.5-Star Gaming Mini PC Just Hit All-Time Low and Extra Coupon Makes It Even Cheaper
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

What cyber defenders can learn from emergency healthcare

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
What cyber defenders can learn from emergency healthcare
December 18, 2025
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?