CVE-2012-4869 describes a critical remote code execution (RCE) vulnerability in FreePBX versions 2.9, 2.10, and earlier. An attacker can exploit the callme_startcall function in recordings/misc/callme_page.php by manipulating the callmenum parameter. This vulnerability carries a CVSS score of 7.5, indicating high severity with network-based exploitation, low attack complexity, and potential for complete compromise of confidentiality, integrity, and availability. Exploitation is highly probable, with a high EPSS score and a FAUCET Risk Score of 99/100. Multiple public exploit modules exist, including a Metasploit module and several entries on ExploitDB, confirming readily available exploit code. While not on the KEV catalog, the vulnerability has garnered significant community discussion and media coverage, including its association with Mirai botnet variants targeting Linux and IoT devices.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.10CPE matchmatch criteria | cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:* | ||
2.9CPE matchmatch criteria | cpe:2.3:a:sangoma:freepbx:2.9:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.