Sceawere

Vulnerability Detail

CVE-2026-108161UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FusionPBX OS Command Injection Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
2h ago
Vendor
fusionpbx
Product
fusionpbx
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
HIGH

Narrative and Response

Description

FusionPBX through 5.6.5 contains an OS command injection vulnerability in call_recordings::download() that allows unauthenticated attackers to execute commands by placing calls with malicious caller ID values. When the record_name filename template is enabled, attackers can embed shell metacharacters like $(...) in the Caller-ID name or number, executing commands as the web server user once a privileged user downloads multiple recordings as a ZIP.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-10-10T14:16:37.223Z",
  "pubdate": "2026-10-10T14:16:37.223Z",
  "executiveSummary": "FusionPBX versions up to 5.6.5 are susceptible to an OS command injection vulnerability located within the call_recordings::download() function.\nThe vulnerability allows an unauthenticated remote attacker to execute arbitrary system commands with the privileges of the web server user.\nThe flaw originates from improper neutralization of user-supplied data, specifically Caller-ID names and numbers, when the system processes call recordings for ZIP archival.\nExploitation requires the record_name filename template to be enabled. By manipulating the Caller-ID metadata with shell metacharacters—such as $(...)—an attacker can trigger command execution when an administrator or privileged user initiates a batch download of recordings.\nThis vulnerability poses a critical risk to the integrity, confidentiality, and availability of the FusionPBX instance. Successful exploitation grants the attacker persistent access to the underlying operating system, potentially leading to full server compromise, lateral movement within the network, and data exfiltration.\nGiven the unauthenticated nature of the initial vector via malicious call metadata, this vulnerability necessitates immediate attention to mitigate remote code execution risks.",
  "technicalDetails": "The vulnerability resides in the call_recordings::download() method within the FusionPBX codebase. The root cause is the insecure handling of dynamic filename generation when creating ZIP archives of call recordings. The application fails to sanitize or escape user-supplied metadata—specifically the Caller-ID name and number fields—before incorporating them into filesystem operations or shell commands.\nWhen the 'record_name' filename template is active, the application constructs file paths or filenames using the tainted Caller-ID data. If an attacker injects shell metacharacters, such as command substitution syntax $(...), into these fields during an inbound or outbound call, the underlying system shell interprets these characters during the archive generation process.\nThe attack flow begins with the injection of a malicious payload into the Caller-ID field, which is subsequently persisted in the FusionPBX database as part of the call record metadata. Because the Caller-ID is often populated via external SIP headers, this can be achieved by an unauthenticated attacker initiating calls through the PBX system. The payload remains dormant in the database until a privileged user, such as an administrator, accesses the call recordings interface and initiates a bulk download or zip operation.\nWhen the application executes the download routine, it invokes system-level utilities to aggregate the recording files into a compressed format. During this process, the shell parses the malicious filename string. The embedded command substitution is executed by the web server process (e.g., www-data or similar). Since the server process is responsible for creating these archives, the commands are executed with the security context and filesystem permissions of the web server user.\nThe exploit does not require the attacker to interact with the administrative interface directly; the secondary, privileged user acts as a functional trigger for the payload. Once the command executes, the attacker may deploy reverse shells, modify configuration files, or perform reconnaissance on the internal network. The vulnerability essentially allows for arbitrary code execution (ACE) on the host operating system, bypassing intended application-level access controls. Affected versions include all releases up to and including 5.6.5, representing a significant security debt in legacy and current installations that have not applied strict input validation for call metadata."
}
CVE-2026-108161: FusionPBX OS Command Injection Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere