Multiple security vulnerabilities have been disclosed in the private branch exchange (PBX) platform, FreePBX, including a critical vulnerability that could lead to authentication bypass (with certain settings).

The vulnerabilities, discovered by Horizon3.ai and reported to the project administrators on September 15, 2025, include:
- CVE-2025-61675 (CVSS score: 8.6) – Multiple SQL injection vulnerabilities affecting four unique endpoints (basestation, model, firmware, and custom extension) and 11 parameters that allow read and write access to the SQL database.
- CVE-2025-61678 (CVSS score: 8.6) – An arbitrary file upload that allows an attacker to exploit the firmware upload endpoint to upload a PHP web shell, after obtaining a valid PHPSESSID. It also allows the execution of arbitrary commands to leak the contents of sensitive files (e.g., “/etc/passwd”).
- CVE-2025-66039 (CVSS score: 9.3) – An authentication bypass vulnerability that occurs when the “Authorization Type” (also known as AUTHTYPE) is set to “webserver”, allowing an attacker to log in to the Admin Control Panel via a forged Authorization header.
See also: Vulnerability in Plesk allows root access

It is worth noting that authentication bypass is not vulnerable in the default FreePBX configuration, since the “Authorization Type” option only appears when the following values in the Advanced Settings Details are set to “Yes”:
- Display Friendly Name
- Display Readonly Settings, and
- Override Readonly Settings
However, if the conditions are met, an attacker can send crafted HTTP requests to bypass authentication and insert a malicious user into the “ampusers” database table. This achieves something similar to CVE-2025-57819, another FreePBX vulnerability that was revealed to have been actively exploited in September 2025.
See also: Google: 5 more Chinese hacking groups exploit React2Shell
“These vulnerabilities are easily exploitable and allow authenticated/unauthenticated remote attackers to achieve remote code execution on vulnerable FreePBX instances,” said Horizon3.ai security researcher Noah King.
The issues have been addressed in the following releases:
- CVE-2025-61675 and CVE-2025-61678 – 16.0.92 and 17.0.6 (Fixed October 14, 2025)
- CVE-2025-66039 – 16.0.44 and 17.0.23 (Fixed December 9, 2025)

Additionally, the option to select a certificate provider has now been removed from Advanced Settings and requires users to set it manually via the command line using fwconsole. As a temporary mitigation, FreePBX has suggested that users set the “Authorization Type” to “usermanager”, set “Override Readonly Settings” to “No”, apply the new setting , and reboot the system to disconnect any malicious sessions.
“If you found that the web server AUTHTYPE was enabled by mistake, then you should fully analyze your system for signs of any potential compromise,” it says.
See also: Windows RasMan vulnerability allows arbitrary code execution
Users also see a warning in the control panel stating that “webserver” may offer reduced security compared to “usermanager.” For optimal protection, it is recommended to avoid using this authorization type.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
