CVE-2026-54674 FreePBX UCP 命令注入漏洞
影响已认证用户可在服务器上以Web用户身份执行任意命令
FreePBX 的 User Control Panel(UCP)在处理特定 URL 参数时未充分过滤恶意字符串,导致命令注入。攻击者通过构造特制 HTTP 请求,可将命令拼接执行,从而在 PBX 主机上以 Web 服务器用户(通常为 asterisk)身份运行任意命令。该漏洞已在 16.0.39 和 17.0.7 版本中修复。
影响范围
FreePBX 16.0.39 之前版本及 17.0.7 之前版本;具体受影响组件为 UCP 模块。
漏洞详情
漏洞类型为命令注入(Command Injection)。成因是 UCP 对某些 URL 参数缺乏充分清理,未完全考虑恶意字符串,攻击者可精心构造命令链,使服务器执行任意二进制程序。利用需要已通过 UCP 认证的账户,但 UCP 访问权限通常比管理员控制面板(ACP)更普遍,低权限用户也可能拥有。
利用条件与风险
利用前提是攻击者拥有有效的 UCP 认证账户;由于 UCP 账户往往比 ACP 账户更易获得,实战中风险较高,可导致服务器被完全控制。
修复建议
官方已在 FreePBX 16.0.39 和 17.0.7 版本中修复,建议尽快升级。临时缓解措施包括限制 UCP 访问权限、监控异常 HTTP 请求,暂无其他公开缓解方案。
FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP) are able to execute arbitrary commands on the PBX as the webserver user (typically asterisk) using specially crafted HTTP strings. Authenticated access to UCP is required. Note that this is often more common for less-privileged users to have UCP access vs. the Administrator Control Panel (ACP) access (which is usually FreePBX higher-level administrator accounts only). Insufficient sanitization of certain URL parameters utilized by UCP did not fully account for malicious strings in these fields. This could result in binaries being executed on the host server by carefully chaining commands. This issue has been patched in versions 16.0.39 and 17.0.7.