---
id: CVE-2025-67513
title: >-
  FreePBX Endpoint Manager is a module for managing telephony endpoints in
  FreePBX systems
summary: >-
  FreePBX Endpoint Manager is a module for managing telephony endpoints in
  FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a
  weak default password. By default, this is a 6 digit numeric value which can
  be brute fo…
severity: none
cwe:
  - CWE-521
published: '2025-12-10'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T23:10:00.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67513'
references:
  - url: >-
      https://github.com/FreePBX/security-reporting/security/advisories/GHSA-426v-c5p7-cp29
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0027
epssPercentile: 0.17178
ingestedAt: '2026-09-25T23:21:16.944Z'
---

## Overview

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this password could be the extension, voicemail, user manager, DPMA or EPM phone admin password. This issue is fixed in versions 16.0.96 and 17.0.10.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
