CVE-2026-75600 FreePBX 命令注入漏洞
影响认证用户可执行任意 shell 命令
FreePBX 是开源 IP PBX 系统。其 API 模块的文档生成器在处理 host 参数时未做校验或转义,直接拼接进 shell 命令,导致已认证且有权访问 GraphQL API 模块的用户可执行任意系统命令。该漏洞已在 17.0.9 版本修复。
影响范围
FreePBX 17.0.9 之前的版本,具体受影响版本范围以官方公告为准。
漏洞详情
漏洞属于命令注入类型。API 模块的文档生成器接收一个已认证的 host 参数,并将其用于构建 shell 命令;代码虽在执行前校验 OAuth 访问令牌,却未对 host 做校验或转义,攻击者可通过构造恶意 host 值注入并执行任意命令。
利用条件与风险
利用需先通过认证并具备访问 API 模块的权限,属于认证后命令注入,成功利用后可以 FreePBX Web/PBX 服务用户(通常为 asterisk)身份执行命令,实战风险较高。
修复建议
官方已在 17.0.9 版本修复,建议升级至该版本或更高版本;临时缓解措施暂无公开信息。
FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module is required. The PBX API module’s documentation generator accepts an authenticated host parameter and uses it to build a shell command. The code path validates the generated OAuth access token before execution, but it does not validate or escape host. Compromise results in authenticated arbitrary shell command execution as the FreePBX web/PBX service user (typically asterisk.). This issue has been patched in version 17.0.9.