CVE-2025-59051 - CVE House
Back to Database
Status published High CVE-2025-59051

FreePBX Endpoint Manager command injection via Network Scanning feature

Vulnerability Description

The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk user. Authentication with a known username is required. Updating to Endpoint Manager 16.0.92 or 17.0.6 addresses the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59051

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

endpoint
Vulnerable Versions:
< 16.0.92, >= 17.0.0, < 17.0.6

Timeline

Official Publish: October 14th, 2025
Last Modified: February 13th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)