CVE-2025-64328
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: freePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. EPSS 85% (100º percentile).
Data di correzione federale CISA 24 feb · data superata
Vulnerabilità · 193 giorni fa
Metasploit Framework 6.4.123 integra due nuovi exploit per AVideo Encoder (CVE-2026-29058) e FreePBX filestore (CVE-2025-64328).
Sfruttamento noto · CISA KEV
CVSS 7.2 HIGH: freePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. EPSS 85% (100º percentile).
Data di correzione federale CISA 24 feb · data superata
CVSS 9.8 CRITICAL: aVideo is a video-sharing Platform software. EPSS 2% (74º percentile).
1 fonte che coprono questa storia
Key additions include new exploit modules for: AVideo Encoder getImage.php Unauthenticated Command Injection (CVE-2026-29058).
Part of the PlainSec briefing for 2026-03-21