OAuth Private Key Vulnerability in FreePBX API Module
CVE-2025-55739
What is CVE-2025-55739?
The FreePBX API module has a vulnerability due to an identical OAuth private key being utilized across various installations of the same FreePBX RPM or DEB package. This flaw affects versions lower than 15.0.13, and from 16.0.2 to 16.0.14, and 17.0.1 and 17.0.2. An attacker with access to the common OAuth private key could forge JSON Web Tokens (JWT), potentially bypassing authentication measures to gain unauthorized access to REST and GraphQL APIs. Systems configured with the 'api' module enabled for remote inbound connections are particularly at risk. The issue has been addressed in later versions, specifically 15.0.13, 16.0.15, and 17.0.3.
Affected Version(s)
api < 15.0.13 < 15.0.13
api >= 16.0.2, < 16.0.15 < 16.0.2, 16.0.15
api >= 17.0.1, < 17.0.3 < 17.0.1, 17.0.3
