ZeroHour

CVE-2025-64328

KEV PoC moderate

Post-Authentication OS Command Injection in Sangoma FreePBX Filestore Module

CISA: Sangoma FreePBX OS Command Injection Vulnerability

CVSS 4.0
8.6 high
EPSS
85%p100
Published
()
KEV added
AI analysis

Sangoma FreePBX's filestore module within the Administrative interface (described alongside the Endpoint Manager module) contains an OS command injection flaw (CWE-78) in its testconnection -> check_ssh_connect() function, affecting versions 17.0.2.36 and above before 17.0.3. An attacker who is already authenticated — CVSS 4.0 scoring indicates high privileges are required — can trigger the test-connection function to inject and execute arbitrary operating-system commands. Successful exploitation gives the attacker remote access to the system as the 'asterisk' user, and in observed attacks this has been leveraged to deploy a weaponized web shell. Any FreePBX deployment running the affected module versions is exposed; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-03, and public reporting ties it to web shell campaigns that have compromised 900+ FreePBX instances. EPSS currently assigns an 84.6% probability of exploitation within 30 days (100th percentile), underscoring the urgency of patching.

What to do: Upgrade the filestore/Endpoint Manager module to version 17.0.3 or later via FreePBX module administration, following vendor instructions — CISA KEV/BOD 22-01 requires applying vendor mitigations or discontinuing use if mitigation is unavailable. Hunt for the weaponized web shell described in Fortinet's referenced research, unexpected files or processes running as the asterisk user, and suspicious activity through the Administrative interface, and restrict admin access to trusted users and networks until patched.

Affected
Sangoma FreePBX (filestore module, per CISA affected-product listing)Deployments running the vulnerable module version 17.0.2.36 or later, prior to 17.0.3
Sangoma FreePBX filestore module (Endpoint Manager)17.0.2.36 and above, before 17.0.3; fixed in 17.0.3
Estimated exposure
moderate≥900 confirmed-compromised FreePBX instances; broader internet-exposed installed base unknown — Public reporting in the source headlines documents 900+ compromised FreePBX instances, but the provided data contains no total install-base or internet-exposure counts, so the plausibly affected population is at least in the low thousands.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.

CISA Known Exploited Vulnerability
Affected
Sangoma FreePBX
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
sangoma
Products
filestore
Weakness
CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news