Urgent: FreePBX Servers Vulnerable to Zero-Day Exploit – Immediate Patching Required!

The developers of an open-source Private Branch Exchange (PBX) platform, Sangoma FreePBX, have issued a warning regarding a zero-day vulnerability that is currently being exploited by malicious actors. On 27 August, the FreePBX security team acknowledged the potential exploit affecting systems with the administrator control panel exposed to the public internet. They announced that a fix was in progress, with an expected deployment within 36 hours. By 28 August, the fix was made available, but the security team advised users to continue restricting access to the administrator control panel.

Despite the prompt response, some users reported significant exploitation of their networks. One user indicated that multiple servers within their infrastructure had been compromised, impacting approximately 3,000 SIP extensions and 500 trunks. Another user cautioned that all systems should be considered compromised, noting that attackers may have been present for nearly a week, potentially causing extensive damage and leaving backdoors in the system. 

Categories: Cybersecurity, Vulnerability Management, Incident Response 

Tags: Vulnerability, Exploit, Security, Administrator, Control Panel, Firewall, Access, Users, Networks, Incident 

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *