Back to Database
Status published
High
CVE-2025-62173
Authenticated SQL Injection in Endpoint Module Rest API
Vulnerability Description
## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62173
Credits & Attribution
No credits recorded in the NVD database.
More from FreePBX
View All →CVE-2025-67736
Authenticated SQL Injection in FreePBX tts (Text To Speech) module
High
8.6
CVE-2025-67722
Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation
Medium
5.7
CVE-2025-67513
FreePBX Endpoint Manager's Weak Default Password Allows Unauthenticated Access in Endpoint Module REST API
Medium
6.9
CVE-2025-66039
FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header
Critical
9.3
CVE-2025-64328
FreePBX Administration GUI is Vulnerable to Authenticated Command Injection
High
8.6
Affected Vendor
FreePBX
View all reports →Affected Software
restapps
Vulnerable Versions:
< 16.0.41, >= 17.0.0, < 17.0.6
Timeline
Official Publish:
December 3rd, 2025
Last Modified:
February 13th, 2026
Added to House:
July 22nd, 2026