FreePBX A.I CyberSecurity Scoring
FreePBX
Company Information
Website:https://www.freepbx.org/
Employees number:None
Number of followers:879
NAICS:517
Industry Type:Telecommunications
Homepage:freepbx.org
FreePBX Risk Score (AI oriented)
Between 750 and 799
FreePBXTelecommunications
Updated:
01/04/2026
01/04/2026
751/1000
Fair
Baa
FreePBX Global Score (TPRM)
xxxx
FreePBXTelecommunications
Score locked

FreePBXFair
Current Score
751Baa (FAIR)
01000
1 incidents
-3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
751
MAY 2026
751
APRIL 2026
751
MARCH 2026
751
FEBRUARY 2026
751
JANUARY 2026
750
DECEMBER 2025
753
Vulnerability
01 Dec 2025 • FreePBX
FreePBX and Indian technology firm: Hackers Exploiting FreePBX Vulnerability to Deploy Webshell and Gain Control of Systems
Sophisticated FreePBX Attack Campaign Deploys Persistent 'EncystPHP' Webshell
750
CRITICAL-3
YASFRE1769690560
Sophisticated FreePBX Attack Campaign Deploys Persistent "EncystPHP" Webshell
A financially motivated hacker group, INJ3CTOR3, has launched a targeted attack campaign exploiting CVE-2025-64328, a critical post-authentication command-injection vulnerability in FreePBX’s Endpoint Manager. The campaign, active since early December 2025, deploys EncystPHP, a highly evasive webshell granting attackers full administrative control over compromised VoIP and PBX systems.
### Exploitation & Attack Chain
The vulnerability, tracked in the Filestore component’s check_ssh_connect() function, allows authenticated attackers to execute arbitrary commands as the asterisk user. Attack traffic originated from Brazil, targeting cloud-based VoIP environments managed by an Indian technology firm.
Threat actors downloaded the EncystPHP dropper from 45[.]234[.]176[.]202, a server masquerading as a VoIP management portal (crm[.]razatelefonia[.]pro). The malware redirects victims to a secondary dropper (k.php) before deploying the webshell.
### EncystPHP Capabilities & Persistence
The webshell, disguised as ajax.php, employs MD5-hashed authentication and an interactive "Ask Master" interface for remote command execution. Key features include:
- Multi-stage persistence: Cron jobs, redundant droppers in /var/www/html/, and forged timestamps to evade detection.
- Privilege escalation: Creates a root-level "newfpbx" account, resets user passwords, and injects SSH keys for backdoor access.
- Evasion techniques: Modifies file permissions, disables error logging, and removes competing malware.
- Telephony abuse: Enumerates SIP peers, Asterisk channels, and initiates unauthorized calls for toll fraud.
### Attribution & Historical Context
INJ3CTOR3, active since 2020, has a history of targeting VoIP systems for financial gain. Previous campaigns exploited:
- CVE-2019-19006 (FreePBX, 2020)
- CVE-2021-45461 (Elastix, 2022)
### Indicators of Compromise (IoCs)
- C2 Infrastructure: `45[.]234[.]176[.]202`, `187[.]108[.]1[.]130`, `crm[.]razatelefonia[.]pro`
- Webshell Hashes:
- `71d94479d58c32d5618ca1e2329d8fa62f930e0612eb108ba3298441c6ba0302` (EncystPHP)
- `7e3a47e3c6b82eb02f6f1e4be6b8de4762194868a8de8fc9103302af7915c574` (Dropper)
- File Paths: `/var/www/html/admin/views/ajax.php`, `/var/www/html/rest_phones/ajax.php`
- Detection Signatures: `PHP/EncystPHP.A!tr`, `IPS Signature 59448`
The attack underscores the persistent targeting of VoIP infrastructure for monetization, with unpatched FreePBX systems at high risk of full compromise.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
REFERENCES
NOVEMBER 2025
753
OCTOBER 2025
753
SEPTEMBER 2025
753
AUGUST 2025
753
JULY 2025
753
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for FreePBX ??
What was FreePBX's A.I Rankiteo Cyber Score in May 2026 ??
What was FreePBX's A.I Rankiteo Cyber Score in April 2026 ??
What was FreePBX's A.I Rankiteo Cyber Score in March 2026 ??
What was FreePBX's A.I Rankiteo Cyber Score in February 2026 ??
What was FreePBX's A.I Rankiteo Cyber Score in January 2026 ??
What was FreePBX's A.I Rankiteo Cyber Score in December 2025 ??
What was FreePBX's A.I Rankiteo Cyber Score in November 2025 ??
What was FreePBX's A.I Rankiteo Cyber Score in October 2025 ??
What was FreePBX's A.I Rankiteo Cyber Score in September 2025 ??
What was FreePBX's A.I Rankiteo Cyber Score in August 2025 ??
What was FreePBX's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on FreePBX's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with FreePBX ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view FreePBX's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?