
Detection for CVE-2025-61675, CVE-2025-61678 & CVE-2025-66039
This repository contains Nuclei templates for detecting three critical vulnerabilities in FreePBX:
These templates detect vulnerable FreePBX instances by:
The detection is non-invasive and does not attempt to exploit the vulnerabilities.
nuclei -u <target-url> -t CVE-2025-61675.yaml
nuclei -u <target-url> -t .
nuclei -l hosts.txt -t .
[CVE-2025-61675] [http] [high] FreePBX Authenticated SQL Injection
[CVE-2025-61678] [http] [high] FreePBX Authenticated Arbitrary File Upload
[CVE-2025-66039] [http] [critical] FreePBX Authentication Bypass
Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
This project is licensed under the MIT License.
If you have any questions about this vulnerability detection script please reach out to me via Signal.