CVE-2025-55211

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-55211
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-55211.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-55211
Aliases
  • GHSA-xg83-m6q5-q24h
Published
2025-09-15T21:00:13.557Z
Modified
2025-12-05T10:20:15.375947Z
Severity
  • 6.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Green CVSS Calculator
Summary
FreePBX Post-Authenticated Command Injection
Details

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/55xxx/CVE-2025-55211.json",
    "cwe_ids": [
        "CWE-78"
    ]
}
References

Affected packages

Git / github.com/freepbx/framework

Affected ranges

Type
GIT
Repo
https://github.com/freepbx/framework
Events

Affected versions

release/17.*

release/17.0.19.11
release/17.0.19.12
release/17.0.19.13
release/17.0.19.14
release/17.0.19.15
release/17.0.19.16
release/17.0.19.17
release/17.0.19.18
release/17.0.19.19
release/17.0.19.20
release/17.0.19.21
release/17.0.19.22
release/17.0.19.23
release/17.0.19.24
release/17.0.19.25
release/17.0.19.26
release/17.0.19.27
release/17.0.19.28
release/17.0.19.29
release/17.0.19.30
release/17.0.19.31
release/17.0.19.32
release/17.0.19.33
release/17.0.19.34
release/17.0.19.35
release/17.0.20
release/17.0.20.1