CVE Database
/

CVE-2025-67513

Back to search

CVE-2025-67513

Published: Dec 10, 2025

Modified: Feb 13, 2026

PUBLISHED

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.

VendorProductVersions

FreePBX

endpoint

affected
< 16.0.96
affected
>= 17.0.1, < 17.0.10

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now