CVE-2026-54708 FreePBX 备份模块 路径遍历代码执行漏洞
影响已认证攻击者可上传恶意 PHP 文件并远程执行任意代码
FreePBX 备份模块在备份恢复功能中存在路径处理不当问题,未对路径进行充分净化。攻击者借助该缺陷可将恶意 PHP 文件写入 Web 根目录,从而在服务器上执行任意代码。官方已在 16.0.72 和 17.0.7 版本中修复。
影响范围
FreePBX 16.0.72 之前版本及 17.0.7 之前版本,涉及备份模块(backup Module)。
漏洞详情
漏洞类型为路径遍历/不安全文件上传导致的远程代码执行。成因是备份恢复功能对上传文件路径缺乏正确净化,攻击者可构造包含路径穿越的备份内容,将 PHP 文件释放到 Web 根目录。随后通过访问该 PHP 文件触发执行,实现任意代码执行。
利用条件与风险
利用需先通过认证,且账号需具备足够权限或对备份文件的写权限,属于已认证攻击者利用。一旦成功即可完全控制服务器,实战风险高。
修复建议
升级至 FreePBX 16.0.72 或 17.0.7 及以上版本。临时缓解措施暂无公开信息,建议限制备份模块访问权限并监控异常文件写入。
FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX backup Module that allows authenticated attackers to execute arbitrary code on the server. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This vulnerability is caused by improper path sanitization in the backup restore functionality, enabling attackers to upload malicious PHP files to the web root directory. This issue has been patched in versions 16.0.72 and 17.0.7.