vulns.comcp

← CVE intelligence

CVE-2025-64328 - Sangoma FreePBX OS Command Injection Vulnerability

Sangoma FreePBX Endpoint Manager contains an OS command injection vulnerability that could allow for a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to potentially obtain remote access to the system as an asterisk user.

Severity
critical
Product
Sangoma FreePBX
Published
2026-02-03
EPSS
0.846
CISA KEV
Known exploited
Ransomware
Known campaign use

References and validation

Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.