CVE-2026-54710 FreePBX superfecta 模块远程代码执行漏洞
影响认证攻击者可远程执行任意 PHP 代码
FreePBX 的 superfecta 模块在 16.0.40 和 17.0.7 之前的版本中存在严重的远程代码执行漏洞。该模块的 AJAX 处理器在 options 和 save_options 分支中,会根据用户输入动态包含 sources/ 目录下的 PHP 文件,且未做安全校验。攻击者结合任意目录创建与文件上传即可执行任意 PHP 代码。
影响范围
FreePBX superfecta 模块 16.0.40 之前版本及 17.0.7 之前版本;官方已在 16.0.40 和 17.0.7 中修复。
漏洞详情
漏洞类型为不安全的 PHP 文件包含导致的远程代码执行。成因是 superfecta 模块 AJAX 处理器的 options 与 save_options 分支直接使用用户可控输入拼接并包含 sources/ 目录下的 PHP 文件,未限制路径或文件名。攻击者可先借助 backup 模块创建任意目录、借助 soundlang 模块上传文件并泄露完整路径,再通过构造输入包含恶意 PHP 文件,从而以 Web 服务器用户权限执行代码。
利用条件与风险
利用需先通过已知用户名的身份认证,并配合目录创建与文件上传等条件,利用链较长但一旦成功可完全控制服务器,实战风险高。
修复建议
升级 FreePBX superfecta 模块至 16.0.40 或 17.0.7 及以上版本。临时缓解可限制对 superfecta 模块 AJAX 接口的访问、加强认证与权限控制,并监控异常文件包含与上传行为。
FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerability exists in the superfecta module due to unsafe inclusion of arbitrary PHP files, allowing authenticated attackers to execute arbitrary PHP code on the server with the privileges of the web server user. Authentication with a known username is required. The vulnerability is rooted in the options and save_options cases in the Superfecta module’s AJAX handler. The code dynamically includes PHP files from the sources/ directory based on user-supplied input. This allows an attacker to execute arbitrary code when combined with arbitrary directory creation (e.g., via the backup module) and file uploads that reveal full paths (e.g., via the soundlang module). This issue has been patched in versions 16.0.40 and 17.0.7.