VYPR
High severity8.8NVD Advisory· Published Sep 15, 2025· Updated Jun 17, 2026

CVE-2025-55211

CVE-2025-55211

Description

FreePBX is an open-source web-based graphical user interface. From 17.0.19.11 to before 17.0.21, authenticated users of the Administrator Control Panel (ACP) can run arbitrary shell commands by maliciously changing languages of the framework module. This vulnerability is fixed in 17.0.21.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Freepbx/Freepbx2 versions
    cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*range: >=17.0.19.11,<17.0.21
    • (no CPE)range: from 17.0.19.11 to before 17.0.21
  • Range: >= 17.0.19.11, < 17.0.21

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.