<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>FusionPBX - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/fusionpbx/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 15:55:04 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/fusionpbx/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>FusionPBX OS Command Injection via Malicious Caller-ID</title><link>https://feed.craftedsignal.io/briefs/2026-10-fusionpbx-command-injection/</link><pubDate>Sat, 10 Oct 2026 15:55:04 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-fusionpbx-command-injection/</guid><description>FusionPBX versions up to 5.6.5 contain an unauthenticated OS command injection vulnerability in the call_recordings::download function, allowing arbitrary code execution via crafted Caller-ID fields.</description><content:encoded><![CDATA[<p>FusionPBX versions through 5.6.5 are susceptible to an OS command injection vulnerability located within the <code>call_recordings::download()</code> function. This vulnerability allows an unauthenticated remote attacker to execute arbitrary system commands by crafting malicious input in the Caller-ID name or number field when placing a call. When the <code>record_name</code> filename template configuration is enabled, the application improperly handles these fields during the process of bundling multiple call recordings into a ZIP file for a privileged user. Because the underlying system processes these filenames, the injected shell metacharacters, such as <code>$(...)</code>, are evaluated by the shell under the context of the web server user. This vulnerability presents a high risk as it permits code execution without requiring administrative authentication on the FusionPBX interface.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to achieve remote command execution with the privileges of the web server user. This could lead to full application compromise, lateral movement within the network, or potential data exfiltration of call recordings. Given FusionPBX's role as a PBX system, this compromise could also facilitate unauthorized interception of voice traffic or manipulation of call routing configurations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade FusionPBX to a version later than 5.6.5 to remediate the vulnerability in <code>call_recordings::download()</code>.</li>
<li>Monitor web server logs for suspicious requests involving the <code>call_recordings</code> module that include shell metacharacters like <code>$(</code>, <code>`</code>, or <code>|</code> in request parameters.</li>
<li>Restrict access to the FusionPBX administrative interface to trusted management networks only, mitigating the ability for external attackers to trigger the ZIP download function.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>command-injection</category><category>web-application</category></item></channel></rss>