← Vulnerability feed

Vulnerability record · CVE-2020-7351 · published 1 May 2020

CVE-2020-7351: Trixbox CE endpoint_devicemap.php OS command injection

Netfortris · Trixbox

Fonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run arbitrary commands on the underlying system as the asterisk user. The product has been unsupported by the vendor since 2012, so no official fix is expected.

8.8 CVSS 3.1 High EPSS 65% · top 0.8% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
65%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityNetwork-reachable command injection with public exploit code and very high EPSS, but no vendor patch exists and the product is end-of-life.

What it is

Fonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run arbitrary commands on the underlying system as the asterisk user. The product has been unsupported by the vendor since 2012, so no official fix is expected.

Impact

An attacker gains command execution on the host as the asterisk user, which can lead to full compromise of the telephony server and any data or credentials it holds.

Attack surface

Reachable over the network through the endpoint_devicemap.php endpoint; the CVSS vector indicates low privileges are required and no user interaction.

Exploitation

Public exploit code exists (Packet Storm and a Metasploit pull request), and EPSS is 0.65208 (99.2nd percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.

What to do

  • There is no vendor patch; Trixbox CE has been unsupported since 2012, so plan migration to a supported platform.
  • Isolate or decommission affected Trixbox CE 1.2.0 through 2.8.0.4 hosts; versions 1.0 and 1.1 are unaffected.
  • Restrict network access to the Trixbox web interface to trusted management networks only.
  • Run the asterisk service and web stack with least privilege and monitor for unexpected child processes.
  • Apply virtual patching or WAF rules blocking command injection patterns against endpoint_devicemap.php.

Detection

  • Monitor web server logs for requests to endpoint_devicemap.php with shell metacharacters or unusual parameters.
  • Alert on child processes spawned by the web server or asterisk user, especially shells or network utilities.
  • Review outbound connections from Trixbox hosts for signs of post-exploitation activity.
  • Search for known exploit payloads or Metasploit module artifacts in process and command-line telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7351 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2017-14535trixbox lang parameter OS command injectiontrixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An…EPSS 50%analysed7.5CVE-2014-5109Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL co…EPSS 3.4%7.5CVE-2014-5112Netfortris trixbox code injection vulnerabilitymaint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.EPSS 9.2%7.5CVE-2010-0702Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands…EPSS 4.2%6.5CVE-2017-14537Netfortris trixbox path traversal vulnerabilitytrixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.…EPSS 39%5.4CVE-2017-14536Netfortris trixbox cross-site scripting vulnerabilitytrixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.EPSS 0.60%5.0CVE-2014-5111Netfortris trixbox path traversal vulnerabilityMultiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parame…EPSS 22%4.3CVE-2014-5110Netfortris trixbox cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HT…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2020-7351), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.