Two critical issues and one high-severity flaw in FreePBX modules sharpen a familiar warning: when the admin layer of a PBX stack breaks, the whole phone system can become the attack surface.
ACN CSIRT Italia has flagged a critical FreePBX vulnerability that could let an attacker bypass authentication on affected systems.
A FreePBX-targeting campaign shows how a web-based PBX admin panel can shift from routine management to a long-lived platform for toll fraud and abuse.
A reported campaign against FreePBX shows how a web admin panel, a shell dropper, and a PHP web shell can combine into a durable foothold on a telephony control plane.
A newly flagged vulnerability in FreePBX’s backup module shows how a routine recovery feature can become a high-risk trust boundary for administrators.