FreePBX patched three serious vulnerabilities in the Endpoint Manager component that can be chained to give an attacker control of a vulnerable system. The issues include CVE-2025-66039, a critical authentication bypass tied to manipulation of the Authorization header to use the webserver authentication type, plus CVE-2025-61675 and **CVE-2025-61678`, two high-severity flaws that enable SQL injection and arbitrary file upload. Researchers reported that, when combined, the bugs can let an unauthenticated attacker read and modify SQL database contents and upload files such as webshells, leading to remote code execution.
The vulnerabilities affect FreePBX 16 before 16.0.44 and 16.0.92, and FreePBX 17 before 17.0.6 and 17.0.23. Reporting indicates the authentication bypass is not exploitable in a standard FreePBX configuration, but organizations with affected deployments were urged to update immediately and apply configuration mitigations where relevant. The disclosures highlight the risk of exposed PBX management components, particularly where Endpoint Manager is enabled and reachable by attackers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
FreePBX developers patched three serious vulnerabilities in the Endpoint Manager component: CVE-2025-66039, CVE-2025-61675, and CVE-2025-61678. The flaws included an authentication bypass, SQL injection, and arbitrary file upload issues affecting FreePBX 16 and 17 releases.
Security researchers at Horizon3.ai reported that chaining the three FreePBX vulnerabilities could let an unauthenticated attacker read and modify SQL database contents and upload files such as webshells to a vulnerable instance. The report also noted CVE-2025-66039 is triggered via manipulation of the Authorization header and is not exploitable in a standard FreePBX configuration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.