FusionPBX OS Command Injection via Malicious Caller-ID
FusionPBX versions up to 5.6.5 contain an unauthenticated OS command injection vulnerability in the call_recordings::download function, allowing arbitrary code execution via crafted Caller-ID fields.
CVE search metadata
CVE search record: CVE-2026-108161. Severity: high. CVSS: 7.5. KEV: no. Product: FusionPBX (<= 5.6.5). Brief: FusionPBX OS Command Injection via Malicious Caller-ID. Brief link: https://feed.craftedsignal.io/briefs/2026-10-fusionpbx-command-injection/
FusionPBX versions through 5.6.5 are susceptible to an OS command injection vulnerability located within the call_recordings::download() function. This vulnerability allows an unauthenticated remote attacker to execute arbitrary system commands by crafting malicious input in the Caller-ID name or number field when placing a call. When the record_name filename template configuration is enabled, the application improperly handles these fields during the process of bundling multiple call recordings into a ZIP file for a privileged user. Because the underlying system processes these filenames, the injected shell metacharacters, such as $(...), are evaluated by the shell under the context of the web server user. This vulnerability presents a high risk as it permits code execution without requiring administrative authentication on the FusionPBX interface.
Impact
Successful exploitation allows unauthenticated attackers to achieve remote command execution with the privileges of the web server user. This could lead to full application compromise, lateral movement within the network, or potential data exfiltration of call recordings. Given FusionPBX's role as a PBX system, this compromise could also facilitate unauthorized interception of voice traffic or manipulation of call routing configurations.
Recommendation
- Upgrade FusionPBX to a version later than 5.6.5 to remediate the vulnerability in
call_recordings::download(). - Monitor web server logs for suspicious requests involving the
call_recordingsmodule that include shell metacharacters like$(,`, or|in request parameters. - Restrict access to the FusionPBX administrative interface to trusted management networks only, mitigating the ability for external attackers to trigger the ZIP download function.
Immediate actions
Upgrade FusionPBX to a version higher than 5.6.5
Mitigations
Upgrade FusionPBX to latest available release
CVE-2026-108161