CVE-2025-64328
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: freePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. EPSS 85% (100º percentile).
Data di correzione federale CISA 24 feb · data superata
Vulnerabilità ed exploit · Attacco ad app web
Metasploit Framework 6.4.123 integra due nuovi exploit per AVideo Encoder (CVE-2026-29058) e FreePBX filestore (CVE-2025-64328).
1 fonte · 20 mar
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: freePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. EPSS 85% (100º percentile).
Data di correzione federale CISA 24 feb · data superata
CVSS 9.8 CRITICAL: aVideo is a video-sharing Platform software. EPSS 2% (74º percentile).
Rapid7
Metasploit Wrap-Up 03/20/2026
Key additions include new exploit modules for: AVideo Encoder getImage.php Unauthenticated Command Injection (CVE-2026-29058).
originalePart of the PlainSec briefing for 2026-03-21
Every edition of this story: Metasploit Aggiunge Moduli Exploit per AVideo e FreePBX