ZeroHour

CVE-2025-57819

KEV PoC mass

Unauthenticated SQL Injection and Auth Bypass Leading to RCE in Sangoma FreePBX 15/16/17

CISA: Sangoma FreePBX Authentication Bypass Vulnerability

CVSS 4.0
10.0 critical
EPSS
85%p100
Published
()
KEV added
AI analysis

FreePBX, Sangoma's open-source web-based GUI for managing PBX systems, is vulnerable in versions 15, 16, and 17 endpoint releases due to insufficiently sanitized user-supplied data (SQL injection, CWE-89, combined with an authentication bypass, CWE-288). An unauthenticated, remote attacker can exploit the flaw without any privileges or user interaction to gain unauthorized access to the FreePBX Administrator interface. From there, the attacker can arbitrarily manipulate the database and ultimately achieve remote code execution on the server. Deployments running affected endpoint versions of FreePBX 15, 16, or 17 are impacted, particularly those with the admin web interface reachable from the internet. The flaw is being actively exploited in the wild: it was added to CISA's KEV catalog on 2025-08-29, a public proof-of-concept is available from watchTowr Labs, and EPSS places it at 85.5% probability of exploitation in the next 30 days (100th percentile).

What to do: Immediately update the FreePBX endpoint package to version 15.0.66, 16.0.89, or 17.0.3 as applicable for each major version in use; federal agencies must follow the CISA BOD 22-01 required actions. Restrict or allowlist access to the FreePBX Administrator web interface at the firewall/reverse proxy level, and review logs for unauthenticated administrator access, unexpected database changes, or uploaded webshells indicating compromise. Treat this as an actively exploited vulnerability given its KEV listing, public PoC, and high EPSS score.

Affected
Sangoma FreePBXFreePBX 15 endpoint versions prior to 15.0.66
Sangoma FreePBXFreePBX 16 endpoint versions prior to 16.0.89
Sangoma FreePBXFreePBX 17 endpoint versions prior to 17.0.3
Estimated exposure
masshundreds of thousands of PBX deployments, with tens of thousands of admin web interfaces likely internet-exposed — FreePBX is one of the most widely deployed open-source PBX management platforms (installed base commonly reported in the hundreds of thousands to millions) and versions 15-17 are the currently supported major lines, whose admin panels are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

CISA Known Exploited Vulnerability
Affected
Sangoma FreePBX
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sangoma
Products
freepbx
Weakness
CWE-89, CWE-288
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news