Sploitus

CVE-2025-66039

8 known exploits for CVE-2025-66039

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23.

Affected products
Freepbx Endpoint Manager
Sangoma Freepbx
< 16.0.44, 17.0.23
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
3.3% (87th percentile)
Weakness
CWE-287
NVD status
Analyzed
Published
2025-12-09
CVE-2025-66039 at NVD
Authoritative description, scoring and affected products

8 known exploits for CVE-2025-66039

Proof-of-concept code and exploit modules indexed by Sploitus