ZeroHour
Security Affairspublished ()ingested @securityaffairs

Experts warn of actively exploited FreePBX zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2025-57819

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-57819
Unauthenticated SQL Injection and Auth Bypass Leading to RCE in Sangoma FreePBX 15/16/17

FreePBX, Sangoma's open-source web-based GUI for managing PBX systems, is vulnerable in versions 15, 16, and 17 endpoint releases due to insufficiently sanitized user-supplied data (SQL injection, CWE-89, combined with an authentication bypass, CWE-288). An unauthenticated, remote attacker can exploit the flaw without any privileges or user interaction to gain unauthorized access to the FreePBX Administrator interface. From there, the attacker can arbitrarily manipulate the database and ultimately achieve remote code execution on the server. Deployments running affected endpoint versions of FreePBX 15, 16, or 17 are impacted, particularly those with the admin web interface reachable from the internet. The flaw is being actively exploited in the wild: it was added to CISA's KEV catalog on 2025-08-29, a public proof-of-concept is available from watchTowr Labs, and EPSS places it at 85.5% probability of exploitation in the next 30 days (100th percentile).

Do: Immediately update the FreePBX endpoint package to version 15.0.66, 16.0.89, or 17.0.3 as applicable for each major version in use; federal agencies must follow the CISA BOD 22-01 required actions. Restrict or allowlist access to the FreePBX Administrator web interface at the firewall/reverse proxy level, and review logs for unauthenticated administrator access, unexpected database changes, or uploaded webshells indicating compromise. Treat this as an actively exploited vulnerability given its KEV listing, public PoC, and high EPSS score.

10.085% KEV PoC
  • Sangoma FreePBX FreePBX 15 endpoint versions prior to 15.0.66
  • Sangoma FreePBX FreePBX 16 endpoint versions prior to 16.0.89
  • Sangoma FreePBX FreePBX 17 endpoint versions prior to 17.0.3
masshundreds of thousands of PBX deployments, with tens of thousands of admin web interfaces likely internet-exposed
Full article376 words · extracted from securityaffairs.com · click to collapse

Sangoma warns of an actively exploited FreePBX zero-day affecting systems with publicly exposed admin control panels.

The Sangoma FreePBX Security Team addressed an actively exploited FreePBX zero-day vulnerability, tracked as CVE-2025-57819 (CVSS score of 10.0), impacting systems with an internet-facing administrator control panel (ACP).

FreePBX is an open-source telephony software platform that provides a web-based graphical interface for managing Asterisk, the most widely used open-source PBX (Private Branch Exchange).

With FreePBX, organizations can set up and manage features like:

  • VoIP (Voice over IP) calls
  • Call routing and extensions
  • Voicemail, call recording, and conferencing
  • Interactive Voice Response (IVR) menus
  • Integration with SIP trunks and phones

Essentially, it turns a standard server (or cloud instance) into a fully functional business phone system.

The root cause of the issue is insufficiently sanitized user-supplied data, which allows unauthenticated access to the FreePBX Administrator, leading to arbitrary database manipulation and remote code execution.

Project administrators revealed that an attacker exploited a flaw in FreePBX v16–17’s “endpoint” module on exposed systems, chaining it with other steps to gain possible root access.

“Starting on or before August 21st, 2025, an unauthorized user began accessing multiple FreePBX version 16 and 17 systems that were connected directly to the public internet — systems with inadequate IP filtering/ACLs — by exploiting a validation/sanitization error in the processing of user-supplied input to the commercial “endpoint” module.” reads the advisory. “This initial entry point was then chained with several other steps to ultimately gain potentially root level access on the target systems.”

The vulnerability impacts:

  • FreePBX 15 prior to 15.0.66
  • FreePBX 16 prior to 16.0.89, and
  • FreePBX 17 prior to 17.0.3

Users are urged to update FreePBX, restrict public ACP access, and check for IoCs, including:

  • File /etc/freepbx.conf recently modified or missing
  • File /var/www/html/.clean.sh should not exist on normal systems
  • POST requests to modular.php in web server logs likely not legitimate traffic
  • Phone calls placed to extension 9998 in call logs and CDRs are unusual – unless previously configured
  • Suspicious ampuser user in the ampusers database table or other unknown users

According to Netlas researchers, most of the potentially vulnerable systems are in the US, followed by Russia and Germany.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181693/hacking/experts-warn-of-actively-exploited-freepbx-zero-day.html