The Non-Invasive Skeleton Key: Inside rxerium/FreePBX-Vulns-December-25

How a handful of YAML templates outpaced global botnets to secure critical telecom infrastructure without firing a single exploit.

6 min read • View on GitHub • More from rxerium

A rotary telephone dial where each finger hole is a heavy steel bank vault door. One door hangs open to reveal sparking wires.
FreePBX vulnerabilities expose critical telecommunications infrastructure to immediate risk.
Key Takeaways

The Race Against the Botnets

When a Private Branch Exchange (PBX) system is compromised, attackers gain more than just data. They gain the ability to route expensive international calls through the victim's infrastructure, a practice known as toll fraud. In December 2025, three critical vulnerabilities in FreePBX were added to the CISA Known Exploited Vulnerabilities catalog. The race between automated botnets and security defenders had begun.

The Oath of Non-Invasion

The immediate response from the security community often involves weaponized exploit scripts. However, running an active SQL injection test on a production telecom server is a terrible idea. It risks crashing the database or leaving behind corrupted data. The rxerium toolkit takes a different architectural approach by relying entirely on passive version fingerprinting.

A stethoscope pressed against a filing cabinet on one side, and a lit stick of dynamite at the base of the identical cabinet on the other.
Passive version fingerprinting provides safe observation, while active exploitation risks structural damage.

Use at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.

rxerium, Maintainer · rxerium/FreePBX-Vulns-December-25

Parsing the Fingerprint

The repository uses the Nuclei scanning engine to execute a series of YAML templates. These templates coordinate a basic GET request and use regular expressions to scrape the FreePBX version string from the HTML body. This ensures the scanner does not misidentify a generic response from a different web service.

matchers:
  - type: word
    part: body
    words:
      - 'FreePBX Administration'
      - 'Operator Panel'
    condition: and

The passive fingerprinting flow safely identifies vulnerable software versions without executing dangerous payloads.

The 'Webserver' Skeleton Key

The highest-scoring vulnerability detected by the suite is CVE-2025-66039. This flaw targets a legacy configuration that allows the AUTHTYPE to equal 'webserver'. When this configuration is active, the system blindly trusts forged client headers, effectively granting administrative access without a password.

Filling the Scanner Gap

This project serves a vital role in the security ecosystem as a point-in-time gap filler. It is faster to deploy than waiting for enterprise scanners to push official updates and vastly safer than downloading a potentially destructive exploit module.

Tool TypeExecution RiskPrimary Action
Nuclei Templates (rxerium)ZeroRegex Version Match
Exploit FrameworksHighPayload Delivery
Enterprise ScannersLowDeep Network Scan