CVE-2026-45562 FreePBX 命令注入漏洞
影响认证管理员可注入命令并以 Asterisk 权限执行任意系统命令
FreePBX 是开源 IP PBX 系统,其 Music on Hold(MoH)模块在 16.0.4 和 17.0.6 之前的版本中存在严重安全缺陷。模块接收定义自定义 Asterisk 应用的 POST 参数,未做任何净化即存入数据库,随后直接写入 musiconhold_additional.conf 配置文件,导致命令注入。
影响范围
FreePBX Music on Hold 模块 16.0.4 之前版本及 17.0.6 之前版本;官方已在 16.0.4 和 17.0.6 中修复。
漏洞详情
漏洞类型为命令注入(配置注入)。成因是 MoH 模块对用户提交的自定义 Asterisk 应用参数缺乏输入校验与过滤,数据未经净化即持久化并写入 Asterisk 配置文件。Asterisk 读取该配置后会执行其中指定的应用,攻击者借此注入任意命令,以 Asterisk 服务权限执行。
利用条件与风险
利用前提是攻击者已持有有效的 FreePBX 管理员账户,属于认证后漏洞。实战中可用于权限提升或横向移动,将 Web 管理权限转化为服务器系统命令执行,风险较高。
修复建议
官方修复方案为升级至 FreePBX Music on Hold 16.0.4 或 17.0.6 及以上版本。临时缓解措施包括限制管理员账户权限与访问来源、审计 musiconhold_additional.conf 配置内容,暂无其他公开缓解信息。
FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a critical security flaw that allows authenticated attackers to execute arbitrary system commands with the privileges of the Asterisk service. Authentication with an existing FreePBX administrator account is required. The root cause lies in the fact that the module accepts a POST parameter that defines a custom Asterisk application, which is then stored in the database without any sanitization. Later, this data is written directly to the musiconhold_additional.conf configuration file without validation. Since Asterisk reads this configuration file and executes the specified application, an attacker can inject arbitrary commands that will be executed with Asterisk’s permissions. This issue has been patched in versions 16.0.4 and 17.0.6.