CVE-2025-59056 Details
Description
FreePBX is an open-source web-based graphical user interface. In FreePBX 15, 16, and 17, malicious connections to the Administrator Control Panel web interface can cause the uninstall function to be triggered for certain modules. This function drops the module's database tables, which is where most modules store their configuration. This vulnerability is fixed in 15.0.38, 16.0.41, and 17.0.21.
A denial-of-service vulnerability has been identified in FreePBX versions 15, 16, and 17. Malicious connections to the Administrator Control Panel can trigger the uninstallation function for certain modules. This action removes the module's database tables, which typically store configuration data. The vulnerability exists due to a lack of authentication and proper validation in the AJAX handler for module management.
Users can update FreePBX to the latest version. For version 15, the patched version is 15.0.38; for version 16, it is 16.0.41; and for version 17, it is 17.0.21. After updating, any missing modules should be reinstalled and data recovered from backups if necessary.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/FreePBX/framework/blame/release/17.0/amp_conf/htdocs/admin/ajax.php#L18 | [email protected] | Product |
| https://github.com/FreePBX/security-reporting/security/advisories/GHSA-frc2-jhgg-rwpr | [email protected] | MitigationThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sangoma freepbx | >= 15.0, < 15.0.38 >= 16.0, < 16.0.41 >= 17.0, < 17.0.21 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 17, 2025 | Initial Analysis | [email protected] |
| Sep 15, 2025 | New CVE Received | [email protected] |