CVE-2025-64328 exploitation impacts 900 Sangoma FreePBX instances
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-64328 | Post-Authentication OS Command Injection in Sangoma FreePBX Filestore Module Sangoma FreePBX's filestore module within the Administrative interface (described alongside the Endpoint Manager module) contains an OS command injection flaw (CWE-78) in its testconnection -> check_ssh_connect() function, affecting versions 17.0.2.36 and above before 17.0.3. An attacker who is already authenticated — CVSS 4.0 scoring indicates high privileges are required — can trigger the test-connection function to inject and execute arbitrary operating-system commands. Successful exploitation gives the attacker remote access to the system as the 'asterisk' user, and in observed attacks this has been leveraged to deploy a weaponized web shell. Any FreePBX deployment running the affected module versions is exposed; CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2026-02-03, and public reporting ties it to web shell campaigns that have compromised 900+ FreePBX instances. EPSS currently assigns an 84.6% probability of exploitation within 30 days (100th percentile), underscoring the urgency of patching. Do: Upgrade the filestore/Endpoint Manager module to version 17.0.3 or later via FreePBX module administration, following vendor instructions — CISA KEV/BOD 22-01 requires applying vendor mitigations or discontinuing use if mitigation is unavailable. Hunt for the weaponized web shell described in Fortinet's referenced research, unexpected files or processes running as the asterisk user, and suspicious activity through the Administrative interface, and restrict admin access to trusted users and networks until patched. | 8.6 | 85% | KEV PoC |
| moderate≥900 confirmed-compromised FreePBX instances; broader internet-exposed installed base unknown |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | crm.razatelefonia.pro | address 45[.]234[.]176[.]202, which resolves to the domain crm[.]razatelefonia[.]pro. “ Attackers delivered the EncystPHP dropper from 45.23 |
| ipv4 | 45.234.176.202 | nia[.]pro. “ Attackers delivered the EncystPHP dropper from 45.234.176.202, exploiting CVE-2025-64328 in FreePBX. Once installed, the |
Full article472 words · extracted from securityaffairs.com · click to collapse

About 900 Sangoma FreePBX systems were infected with web shells after attackers exploited a command injection flaw.
Hundreds of Sangoma FreePBX instances are still infected with web shells following attacks that began in December 2025.
Sangoma FreePBX is an open-source, web-based platform for managing Asterisk-powered VoIP phone systems. Maintained by Sangoma Technologies, it allows businesses to configure extensions, call routing, voicemail, IVR menus, and SIP trunks through an easy-to-use interface.
The campaign exploited a post-authentication command injection vulnerability, tracked as CVE-2025-64328 (CVSS score of 8.6), in the endpoint manager interface, allowing attackers to execute malicious commands and maintain persistent access to compromised systems.
“FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function.” reads the advisory. “An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.”
The Shadowserver Foundation reports that around 900 FreePBX instances are still compromised and running web shells, likely due to exploitation of CVE-2025-64328 in the endpoint manager. About 400 affected systems are located in the United States, with dozens more in countries including Brazil, Canada, Germany, France, the UK, Italy, and the Netherlands, and smaller numbers spread across other regions.
In January, FortiGuard Labs identified a new web shell dubbed “EncystPHP,” capable of remote command execution, persistence, and further web shell deployment. The attacks began in early December and exploited the flaw CVE-2025-64328. Researchers link the activity to the threat group INJ3CTOR3, known for targeting past vulnerabilities in FreePBX and Elastix systems. The campaign follows a familiar pattern: exploiting a flaw and installing a PHP web shell to maintain access.
“The web shell was delivered via CVE-2025-64328, a post-authentication command-injection vulnerability in the administrative interface of the FreePBX Endpoint Manager.” reads the analysis published by Fortinet. “The attackers downloaded the EncystPHP dropper from the IP address 45[.]234[.]176[.]202, which resolves to the domain crm[.]razatelefonia[.]pro. “
Attackers delivered the EncystPHP dropper from 45.234.176.202, exploiting CVE-2025-64328 in FreePBX. Once installed, the malware locked key files, harvested database configs, deleted cron jobs and user accounts, and removed rival web shells. It created a root-level user, reset passwords, injected an SSH key, and ensured port 22 stayed open for persistent access.
The dropper also fetched additional payloads, erased logs, removed the Endpoint Manager module, restored permissions to avoid detection, and deployed Base64-encoded web shells to maintain long-term control.
In early February, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw in Sangoma FreePBX to its Known Exploited Vulnerabilities (KEV) catalog.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CVE-2025-64328 )
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/188679/uncategorized/cve-2025-64328-exploitation-impacts-900-sangoma-freepbx-instances.html