CVE-2025-61675 - CVE House
Back to Database
Status published High CVE-2025-61675

FreePBX Endpoint Manager vulnerable to authenticated SQL injection in multiple configuration parameters

Vulnerability Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model, firmware, and custom extension configuration functionality areas. Authentication with a known username is required to exploit these vulnerabilities. Successful exploitation allows authenticated users to execute arbitrary SQL queries against the database, potentially enabling access to sensitive data or modification of database contents. This issue has been patched in version 16.0.92 for FreePBX 16 and version 17.0.6 for FreePBX 17.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-61675

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

endpoint
Vulnerable Versions:
< 16.0.92, >= 17.0.0, < 17.0.6

Timeline

Official Publish: October 14th, 2025
Last Modified: February 13th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)