CVE-2025-59051 | FreePBX Endpoint Manager up to 16.0.91/17.0.5 Web-based Access os command injection (GHSA-qgj3-f9gj-98v9)
A vulnerability, which was classified as critical, has been found in FreePBX Endpoint Manager up to 16.0.91/17.0.5. This affects an unknown part of the component Web-based Access. Performing manipulation results in os command injection.
This vulnerability is cataloged as CVE-2025-59051. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.