Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection
Vulnerability Description
Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user. This issue affects CompletePBX: all versions up to and prior to 5.2.35
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-30004
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Valentin Lobstein (Chocapikk)
References
Affected Vendor
Xorcom
View all reports →