CVE-2025-55211 MEDIUM

CVE-2025-55211: FreePBX Post-Authenticated Command Injection

Vendor Freepbx
Product framework
Weakness CWE-78
Published September 15, 2025
Last update February 13, 2026

CVSS base score

6.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/AU:N/R:U/V:D/RE:L/U:Green

What the vulnerability does

01Description

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.

Key dates

02Disclosure timeline

September 15, 2025 CVE published
February 13, 2026 Record updated