CVE-2025-64328
KEV PoC moderatePost-Authentication OS Command Injection in Sangoma FreePBX Filestore Module
CISA: Sangoma FreePBX OS Command Injection Vulnerability
Sangoma FreePBX's filestore module within the Administrative interface (described alongside the Endpoint Manager module) contains an OS command injection flaw (CWE-78) in its testconnection -> check_ssh_connect() function, affecting versions 17.0.2.36 and above before 17.0.3. An attacker who is already authenticated — CVSS 4.0 scoring indicates high privileges are required — can trigger the test-connection function to inject and execute arbitrary operating-system commands. Successful exploitation gives the attacker remote access to the system as the 'asterisk' user, and in observed attacks this has been leveraged to deploy a weaponized web shell. Any FreePBX deployment running the affected module versions is exposed; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-03, and public reporting ties it to web shell campaigns that have compromised 900+ FreePBX instances. EPSS currently assigns an 84.6% probability of exploitation within 30 days (100th percentile), underscoring the urgency of patching.
What to do: Upgrade the filestore/Endpoint Manager module to version 17.0.3 or later via FreePBX module administration, following vendor instructions — CISA KEV/BOD 22-01 requires applying vendor mitigations or discontinuing use if mitigation is unavailable. Hunt for the weaponized web shell described in Fortinet's referenced research, unexpected files or processes running as the asterisk user, and suspicious activity through the Administrative interface, and restrict admin access to trusted users and networks until patched.
| Sangoma FreePBX (filestore module, per CISA affected-product listing) | Deployments running the vulnerable module version 17.0.2.36 or later, prior to 17.0.3 |
| Sangoma FreePBX filestore module (Endpoint Manager) | 17.0.2.36 and above, before 17.0.3; fixed in 17.0.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.
- Affected
- Sangoma FreePBX
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- sangoma
- Products
- filestore
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X