Vulnerability record · CVE-2020-7351 · published 1 May 2020
CVE-2020-7351: Trixbox CE endpoint_devicemap.php OS command injection
Netfortris · Trixbox
Fonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run arbitrary commands on the underlying system as the asterisk user. The product has been unsupported by the vendor since 2012, so no official fix is expected.
Description
An OS Command Injection vulnerability in the endpoint_devicemap.php component of Fonality Trixbox Community Edition allows an attacker to execute commands on the underlying operating system as the "asterisk" user. Note that Trixbox Community Edition has been unsupported by the vendor since 2012. This issue affects: Fonality Trixbox Community Edition, versions 1.2.0 through 2.8.0.4. Versions 1.0 and 1.1 are unaffected.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable command injection with public exploit code and very high EPSS, but no vendor patch exists and the product is end-of-life.
What it is
Fonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run arbitrary commands on the underlying system as the asterisk user. The product has been unsupported by the vendor since 2012, so no official fix is expected.
Impact
An attacker gains command execution on the host as the asterisk user, which can lead to full compromise of the telephony server and any data or credentials it holds.
Attack surface
Reachable over the network through the endpoint_devicemap.php endpoint; the CVSS vector indicates low privileges are required and no user interaction.
Exploitation
Public exploit code exists (Packet Storm and a Metasploit pull request), and EPSS is 0.65208 (99.2nd percentile), indicating high likelihood of exploitation. It is not listed in CISA KEV.
What to do
- There is no vendor patch; Trixbox CE has been unsupported since 2012, so plan migration to a supported platform.
- Isolate or decommission affected Trixbox CE 1.2.0 through 2.8.0.4 hosts; versions 1.0 and 1.1 are unaffected.
- Restrict network access to the Trixbox web interface to trusted management networks only.
- Run the asterisk service and web stack with least privilege and monitor for unexpected child processes.
- Apply virtual patching or WAF rules blocking command injection patterns against endpoint_devicemap.php.
Detection
- Monitor web server logs for requests to endpoint_devicemap.php with shell metacharacters or unusual parameters.
- Alert on child processes spawned by the web server or asterisk user, especially shells or network utilities.
- Review outbound connections from Trixbox hosts for signs of post-exploitation activity.
- Search for known exploit payloads or Metasploit module artifacts in process and command-line telemetry.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157565/TrixBox-CE-2.8.0.4-Command-Execution.html | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/13353 | ExploitIssue TrackingPatchThird Party Advisory |
| http://packetstormsecurity.com/files/157565/TrixBox-CE-2.8.0.4-Command-Execution.html | ExploitThird Party Advisory |
| https://github.com/rapid7/metasploit-framework/pull/13353 | ExploitIssue TrackingPatchThird Party Advisory |
Track CVE-2020-7351 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7351), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.