CVE-2025-30004: Xorcom CompletePBX <= 5.2.35 Task Scheduler Authenticated Command Injection

9.1 CVSS

Description

Xorcom CompletePBX is vulnerable to command injection in the administrator Task Scheduler functionality, allowing for attackers to execute arbitrary commands as the root user.

This issue affects CompletePBX: all versions up to and prior to 5.2.35

Classification

CVE ID: CVE-2025-30004

CVSS Base Severity: CRITICAL

CVSS Base Score: 9.1

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Problem Types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products

Vendor: Xorcom

Product: CompletePBX

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.23% (probability of being exploited)

EPSS Percentile: 45.78% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-30004
https://vulncheck.com/advisories/completepbx-authenticated-command-injection
https://www.xorcom.com/new-completepbx-release-5-2-36-1/

Timeline