关键漏洞信息 漏洞概述 漏洞类型: Authenticated SQL Injections in Endpoint Management CVE ID: CVE-2025-61675 CVSS 评分: - CVSS v4.0 Base Score: 8.6 (High) - CVSS v4.0 More Complete Score: 6.1 (Medium) - Alternative CVSS v4.1 Score: 0.9 (Low) 影响版本 FreePBX 16: < 16.0.92 FreePBX 17: < 17.0.6 修复版本 FreePBX 16: 16.0.92 FreePBX 17: 17.0.6 漏洞描述 SQL injection vulnerabilities exist in the FreePBX Endpoint Management module affecting multiple parameters in the following configuration functionality areas: basestation model firmware custom extension Authentication with a known username is required. 缓解措施 Update to the latest fixed version of the endpoint module. Protect your ACP from suspicious users. Remove users that should not have access. Firewall your FreePBX ACP HTTP/HTTPS/GraphQL ports. CVSS v4.0 基本指标 攻击向量: Network 攻击复杂度: Low 攻击需求: None 所需权限: High 用户交互: None 受影响系统影响指标 机密性: High 完整性: High 可用性: Low 后续系统影响指标 机密性: None 完整性: None 可用性: None