Vulnerability record · CVE-2025-57819 · published 28 August 2025
CVE-2025-57819: FreePBX unauthenticated SQL injection and auth bypass to RCE
Sangoma · Freepbx
FreePBX 15, 16 and 17 fail to sanitize user-supplied data, letting an unauthenticated attacker bypass authentication to the FreePBX Administrator interface. That access permits arbitrary database manipulation and remote code execution. The flaw is remotely reachable with no credentials and no user interaction, and it was added to CISA KEV one day after publication.
Description
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a CVSS 4.0 score of 10, KEV listing and a public exploit makes this an immediate patch-or-isolate case.
What it is
FreePBX 15, 16 and 17 fail to sanitize user-supplied data, letting an unauthenticated attacker bypass authentication to the FreePBX Administrator interface. That access permits arbitrary database manipulation and remote code execution. The flaw is remotely reachable with no credentials and no user interaction, and it was added to CISA KEV one day after publication.
Impact
An attacker gains administrative control of the FreePBX system, can alter or exfiltrate the database, and can execute arbitrary code on the host. This exposes call detail records, extensions, credentials and the underlying telephony infrastructure.
Attack surface
Reached over the network against exposed FreePBX Administrator endpoints; the CVSS 4.0 vector shows PR:N and UI:N, so no authentication or user interaction is required. Any internet- or network-reachable FreePBX 15, 16 or 17 instance is in scope.
Exploitation
Listed in CISA KEV with a 2025-09-19 remediation due date, and a public proof-of-concept exploit is referenced by watchTowr. EPSS is 0.85463 (99.7th percentile), indicating very high likelihood of exploitation activity.
What to do
- Upgrade to FreePBX endpoint versions 15.0.66, 16.0.89 or 17.0.3 as the primary fix.
- Restrict Administrator interface access to trusted management networks or VPN and block public exposure until patched.
- Apply the vendor mitigation guidance in the FreePBX security advisory and GitHub advisory GHSA-m42g-xg4c-5f3h.
- Rotate FreePBX administrator, database and any credentials stored on affected systems, and review for unauthorized changes.
- If patching or mitigation is not possible, discontinue use of the exposed product per CISA BOD 22-01 guidance.
Detection
- Review web server and FreePBX logs for unauthenticated requests to Administrator endpoints, especially unusual parameters or SQL-like payloads.
- Monitor database activity for unexpected schema changes, new admin users or bulk data reads.
- Hunt for unexpected processes, web shells or outbound connections originating from the FreePBX host.
- Alert on Administrator interface access from untrusted or external source IP addresses.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-57819 to the Known Exploited Vulnerabilities catalog on 29 August 2025 as "Sangoma FreePBX Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 September 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203 | Issue TrackingVendor Advisory |
| https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h | MitigationVendor Advisory |
| https://github.com/watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-57819 | US Government Resource |
Track CVE-2025-57819 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-57819), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.