CVE-2025-57819
KEV PoC massUnauthenticated SQL Injection and Auth Bypass Leading to RCE in Sangoma FreePBX 15/16/17
CISA: Sangoma FreePBX Authentication Bypass Vulnerability
FreePBX, Sangoma's open-source web-based GUI for managing PBX systems, is vulnerable in versions 15, 16, and 17 endpoint releases due to insufficiently sanitized user-supplied data (SQL injection, CWE-89, combined with an authentication bypass, CWE-288). An unauthenticated, remote attacker can exploit the flaw without any privileges or user interaction to gain unauthorized access to the FreePBX Administrator interface. From there, the attacker can arbitrarily manipulate the database and ultimately achieve remote code execution on the server. Deployments running affected endpoint versions of FreePBX 15, 16, or 17 are impacted, particularly those with the admin web interface reachable from the internet. The flaw is being actively exploited in the wild: it was added to CISA's KEV catalog on 2025-08-29, a public proof-of-concept is available from watchTowr Labs, and EPSS places it at 85.5% probability of exploitation in the next 30 days (100th percentile).
What to do: Immediately update the FreePBX endpoint package to version 15.0.66, 16.0.89, or 17.0.3 as applicable for each major version in use; federal agencies must follow the CISA BOD 22-01 required actions. Restrict or allowlist access to the FreePBX Administrator web interface at the firewall/reverse proxy level, and review logs for unauthenticated administrator access, unexpected database changes, or uploaded webshells indicating compromise. Treat this as an actively exploited vulnerability given its KEV listing, public PoC, and high EPSS score.
| Sangoma FreePBX | FreePBX 15 endpoint versions prior to 15.0.66 |
| Sangoma FreePBX | FreePBX 16 endpoint versions prior to 16.0.89 |
| Sangoma FreePBX | FreePBX 17 endpoint versions prior to 17.0.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
- Affected
- Sangoma FreePBX
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sangoma
- Products
- freepbx
- Weakness
- CWE-89, CWE-288
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X