Weak Default Password Vulnerability in FreePBX Endpoint Manager
CVE-2025-67513
What is CVE-2025-67513?
The FreePBX Endpoint Manager, a module designed for managing telephony endpoints in FreePBX systems, exhibits a serious security issue due to a weak default password. This six-digit numeric password, which serves as the app_password parameter, can be easily brute-forced, exposing systems to unauthorized access. The vulnerability affects specific versions prior to 16.0.96 and the range of 17.0.1 to 17.0.9. Users are encouraged to upgrade to versions 16.0.96 or 17.0.10, where this issue has been resolved, to enhance their system security and protect against potential intrusions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-reporting < 16.0.96 < 16.0.96
security-reporting >= 17.0.1, < 17.0.10 < 17.0.1, 17.0.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
