FusionPBX OS command injection via caller ID
FusionPBX through 5.6.5 allows unauthenticated OS command execution via crafted caller IDs processed in the call_recordings::download() function.
- Vendor
- FusionPBX
- Product
- FusionPBX (through 5.6.5)
- CVSS
- 7.5
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
FusionPBX versions through 5.6.5 contain an OS command injection vulnerability in the call_recordings::download() function. Caller ID data supplied by an unauthenticated caller is passed to a system call without sanitization. An attacker can exploit this by placing a call with a crafted caller ID string containing shell metacharacters.
No authentication is required. The attack vector is the telephony layer, meaning any system accepting inbound calls from untrusted sources is exposed.
Update FusionPBX beyond 5.6.5. If patching is not immediately possible, restrict inbound call routes to trusted SIP trunks and block arbitrary inbound SIP traffic at the network perimeter.
Source: NVD CVE-2026-108161 | FusionPBX on GitHub
