← back
CVE-2025-2292mediumCWE-22

Xorcom CompletePBX <= 5.2.35 Authenticated File Disclosure

28Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 6.5epss 1.6%
from disclosure to weapon0 days
Published on NVDMar 31
metasploitMar 2
exploitation probability
1.6%top 25% of all CVEs
observed exploitation
nono source reports it
Xorcom CompletePBX is vulnerable to an authenticated path traversal, allowing for arbitrary file reads via the Backup and Restore functionality.This issue affects CompletePBX: through 5.2.35.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Xorcom · CompletePBX