{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/fusionpbx/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fusionpbx:fusionpbx:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-108161"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FusionPBX (\u003c= 5.6.5)"],"_cs_severities":["high"],"_cs_tags":["remote-code-execution","command-injection","web-application"],"_cs_type":"advisory","_cs_vendors":["FusionPBX"],"content_html":"\u003cp\u003eFusionPBX versions through 5.6.5 are susceptible to an OS command injection vulnerability located within the \u003ccode\u003ecall_recordings::download()\u003c/code\u003e function. This vulnerability allows an unauthenticated remote attacker to execute arbitrary system commands by crafting malicious input in the Caller-ID name or number field when placing a call. When the \u003ccode\u003erecord_name\u003c/code\u003e filename template configuration is enabled, the application improperly handles these fields during the process of bundling multiple call recordings into a ZIP file for a privileged user. Because the underlying system processes these filenames, the injected shell metacharacters, such as \u003ccode\u003e$(...)\u003c/code\u003e, are evaluated by the shell under the context of the web server user. This vulnerability presents a high risk as it permits code execution without requiring administrative authentication on the FusionPBX interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to achieve remote command execution with the privileges of the web server user. This could lead to full application compromise, lateral movement within the network, or potential data exfiltration of call recordings. Given FusionPBX's role as a PBX system, this compromise could also facilitate unauthorized interception of voice traffic or manipulation of call routing configurations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade FusionPBX to a version later than 5.6.5 to remediate the vulnerability in \u003ccode\u003ecall_recordings::download()\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious requests involving the \u003ccode\u003ecall_recordings\u003c/code\u003e module that include shell metacharacters like \u003ccode\u003e$(\u003c/code\u003e, \u003ccode\u003e`\u003c/code\u003e, or \u003ccode\u003e|\u003c/code\u003e in request parameters.\u003c/li\u003e\n\u003cli\u003eRestrict access to the FusionPBX administrative interface to trusted management networks only, mitigating the ability for external attackers to trigger the ZIP download function.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T15:55:04Z","date_published":"2026-10-10T15:55:04Z","id":"https://feed.craftedsignal.io/briefs/2026-10-fusionpbx-command-injection/","summary":"FusionPBX versions up to 5.6.5 contain an unauthenticated OS command injection vulnerability in the call_recordings::download function, allowing arbitrary code execution via crafted Caller-ID fields.","title":"FusionPBX OS Command Injection via Malicious Caller-ID","url":"https://feed.craftedsignal.io/briefs/2026-10-fusionpbx-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - FusionPBX","version":"https://jsonfeed.org/version/1.1"}