CVE Database
/

CVE-2025-59051

Back to search

CVE-2025-59051

Published: Oct 14, 2025

Modified: Feb 13, 2026

PUBLISHED

Description

The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk user. Authentication with a known username is required. Updating to Endpoint Manager 16.0.92 or 17.0.6 addresses the issue.

VendorProductVersions

FreePBX

endpoint

affected
< 16.0.92
affected
>= 17.0.0, < 17.0.6

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now