A remote command execution vulnerability exists in FreePBX versions 2.9, 2.10, and earlier, specifically in the callme_startcall function within recordings/misc/callme_page.php. The vulnerability is due to insufficient input validation of the 'callmenum' parameter when processing a 'c' action, allowing remote attackers to inject and execute arbitrary system commands on the server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Python exploit script (exploit.py) and a README.md for CVE-2012-4869, a Local File Inclusion (LFI) vulnerability in Elastix 2.2.0. The exploit targets the /recordings/misc/callme_page.php endpoint, leveraging LFI and command injection to execute a Perl reverse shell payload. The attacker supplies their own IP (LHOST) and port (LPORT), and the script crafts a malicious URL that, when accessed by the vulnerable Elastix server, causes it to connect back to the attacker's machine with a root shell. The exploit disables TLS certificate verification to support HTTPS targets and suppresses related warnings. The README provides detailed usage instructions, including setting up a Netcat listener to catch the reverse shell. The repository is straightforward, with a single exploit script and documentation, and is operational with a hardcoded Perl payload that can be modified if needed.
This repository contains a single Metasploit module (freepbx_callmenum.rb) that exploits a remote code execution vulnerability in FreePBX versions 2.10.0, 2.9.0, and possibly older. The exploit targets the 'callme_page.php' script, abusing the 'callmenum' parameter to inject system commands. The attacker must specify a range of extension numbers, as a valid extension is required for exploitation. The exploit sends crafted HTTP GET requests to the vulnerable endpoint, and if successful, executes arbitrary commands on the target server. The module is operational and provides remote command execution capabilities. The only fingerprintable endpoint is the '/recordings/misc/callme_page.php' path on the target FreePBX server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.