選單換圖效果,請啟用Active Scripting功能
南臺首頁 English
:::
訪客 未來學生 本校學生 教職同仁 畢業校友
:::
  南臺頭條新聞
  南臺影音新聞
  所有訊息
  重要公告
  行政公告
  校園活動
  專案計劃
  研討會資訊
  校內徵才
  校園職場實習
  工作機會
  國際證照
  南臺新生
  招生資訊
  南臺RSS新聞
  本月公告一覽
  停刊公告活動欄
  [公告系統登入]


【行政公告】 ::: [ 上一頁 ]
 
公 告 單位
圖資處數位服務組
訊 息 類 別 行政公告 行政公告 公 告 對 象 全體
公 告 主 題
【資安漏洞預警】FreePBX存在高風險安全漏洞(CVE-2025-57819),請儘速確認並進行修補
[Security Vulnerability Alert] FreePBX has a high-risk security vulnerability (CVE-2025-57819). Please confirm and patch it as soon as possible.
公 告 內 容
轉發 國家資安資訊分享與分析中心 NISAC-200-202509-00000006

研究人員發現FreePBX,此用於管理Asterisk系統之Web管理介面工具,存在驗證繞過(Authentication Bypass)漏洞(CVE-2025-57819),未經身分鑑別之遠端攻擊者可直接存取管理者功能,進而控制資料庫與執行任意程式碼。該漏洞已遭駭客利用,請儘速確認並進行修補。

備註:Asterisk為開放原始碼之使用者交換機(PBX)系統軟體,包含網路電話(VoIP)功能,除運作一般電腦外,亦可運作於OpenWRT之類的嵌入式系統上。

[影響平台]
● FreePBX 15至15.0.66(不含)版本  
● FreePBX 16至16.0.89(不含)版本
● FreePBX 17至17.0.3(不含)版本

[建議措施]
官方已針對漏洞釋出修復更新,請參考官方說明,網址如下:
https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h
 
[參考資料]
1. https://nvd.nist.gov/vuln/detail/CVE-2025-57819
2. https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h

Forwarded by the National Information Security Information Sharing and Analysis Center (NISAC-200-202509-00000006)

Researchers have discovered an authentication bypass vulnerability (CVE-2025-57819) in FreePBX, a web-based management interface tool for Asterisk systems. This vulnerability allows an unauthenticated remote attacker to directly access administrator functions, potentially controlling the database and executing arbitrary code. This vulnerability has been exploited by hackers. Please confirm and patch it as soon as possible.

Note: Asterisk is open-source private branch exchange (PBX) system software that includes VoIP functionality. It can run on standard computers as well as embedded systems such as OpenWRT.

[Affected Platforms]
● FreePBX versions 15 to 15.0.66 (excluding)
● FreePBX versions 16 to 16.0.89 (excluding)
● FreePBX versions 17 to 17.0.3 (excluding)

[Recommended Actions]
A fix has been released for this vulnerability. Please refer to the official announcement at the following URL:
https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h

[References]
1. https://nvd.nist.gov/vuln/detail/CVE-2025-57819
2. https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h
相 關 訊 息


公 告 時 間
 2025/9/4   至 2026/3/4   
點 閱 次 數
141

:::
 
地址:71005 台南市永康區南台街一號 (開車訪客請由中正南路→正南一街→進入南臺科技大學) HyperLink