Should I use FusionPBX?
Open-source multi-tenant PBX GUI for FreeSWITCH - fusionpbx.com
Depends. A strong free choice if you are an ITSP or IT team with Linux, FreeSWITCH, and SIP skills who wants a self-hosted multi-tenant phone system. Skip it if you want plug-and-play phones or vendor-managed security — a hosted VoIP service is the better buy.
Confidence
Medium. Based on ~20 public sources: Reddit/forum threads, official docs and site, GitHub, and NVD/Exploit-DB.
Ratings
- Value for money
- Ease of use
- Feature depth
- Support quality
- Security posture
Pricing
Free
Open source (self-hosted)
ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
FusionPBX MembershipNot listed in reviewed sources
Best for
- →ITSPs and resellers running hosted multi-tenant PBX
- →IT teams with Linux and SIP experience
- →Budget-driven self-hosters replacing legacy phone systems
- →Hobbyists — it even runs on a Raspberry Pi
Not for
- ×Small offices wanting plug-and-play phones
- ×Non-technical buyers with no Linux admin
- ×Teams needing vendor SLAs and managed updates
- ×Anyone unwilling to own PBX security hardening
Gotchas - check before you buy
high
Self-hosted: firewalling, fail2ban, and TLS hardening are entirely your job
high
Older versions have public RCE exploits; run current release and restrict web access
medium
Billing is not built in; expect third-party add-ons like ASTPP
medium
Support quality hinges on paid membership; confirm what your tier includes first
Pros and cons
Pros
- +Free, open-source, full-featured multi-tenant PBX
- +No per-seat license cost, per community reports
- +Light enough to run on a Raspberry Pi
- +Favorite pick in on-prem PBX community threads
Cons
- −History of serious CVEs, including public RCE exploits
- −Setup is involved enough to need lengthy community 'taming' guides
- −Newcomers depend on scattered community resources and forums
- −Community actively recommends newer forks like FS PBX
Sources & method
Analyzed 9/25/2026 - 11 sources - Self-hosted software with a track record of CVEs since 2019, including RCE; hardening is the operator's responsibility.
official x4review x4security x2news x1
- Remote code execution in 4.5.29, Public exploit published for FusionPBX 4.5.29 RCE.
- CVE-2024-23387, Affects FusionPBX prior to 5.1.0.
- CVE-2020-21055 directory traversal, Publicly disclosed directory traversal vulnerability.
- Operator Panel command execution, Public Metasploit module targets command execution.
Comments
One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.
No comments yet.