CVE-2025-62173: FreePBX Restapps

High severity, CVSS 8.6. EPSS: 0.3% chance of exploitation in the next 30 days.

## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API

Affected products

  • FreePBX Restapps: before 16.0.41 (fixed in 16.0.41); from 17.0.0, before 17.0.6 (fixed in 17.0.6)

Published 2025-12-04. Last modified 2026-09-25.