← Vulnerability feed

Vulnerability record · CVE-2025-57819 · published 28 August 2025

CVE-2025-57819: FreePBX unauthenticated SQL injection and auth bypass to RCE

Sangoma · Freepbx

FreePBX 15, 16 and 17 fail to sanitize user-supplied data, letting an unauthenticated attacker bypass authentication to the FreePBX Administrator interface. That access permits arbitrary database manipulation and remote code execution. The flaw is remotely reachable with no credentials and no user interaction, and it was added to CISA KEV one day after publication.

10.0 CVSS 4.0 Critical CISA KEV since 29 Aug 2025 EPSS 85% · top 0.3% CWE-89 · SQL injectionCWE-288 · Authentication bypass via alternate path
10.0CVSS 4.0 base score
85%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
26 Sep 2026Last modified by NVD

Description

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a CVSS 4.0 score of 10, KEV listing and a public exploit makes this an immediate patch-or-isolate case.

What it is

FreePBX 15, 16 and 17 fail to sanitize user-supplied data, letting an unauthenticated attacker bypass authentication to the FreePBX Administrator interface. That access permits arbitrary database manipulation and remote code execution. The flaw is remotely reachable with no credentials and no user interaction, and it was added to CISA KEV one day after publication.

Impact

An attacker gains administrative control of the FreePBX system, can alter or exfiltrate the database, and can execute arbitrary code on the host. This exposes call detail records, extensions, credentials and the underlying telephony infrastructure.

Attack surface

Reached over the network against exposed FreePBX Administrator endpoints; the CVSS 4.0 vector shows PR:N and UI:N, so no authentication or user interaction is required. Any internet- or network-reachable FreePBX 15, 16 or 17 instance is in scope.

Exploitation

Listed in CISA KEV with a 2025-09-19 remediation due date, and a public proof-of-concept exploit is referenced by watchTowr. EPSS is 0.85463 (99.7th percentile), indicating very high likelihood of exploitation activity.

What to do

  • Upgrade to FreePBX endpoint versions 15.0.66, 16.0.89 or 17.0.3 as the primary fix.
  • Restrict Administrator interface access to trusted management networks or VPN and block public exposure until patched.
  • Apply the vendor mitigation guidance in the FreePBX security advisory and GitHub advisory GHSA-m42g-xg4c-5f3h.
  • Rotate FreePBX administrator, database and any credentials stored on affected systems, and review for unauthorized changes.
  • If patching or mitigation is not possible, discontinue use of the exposed product per CISA BOD 22-01 guidance.

Detection

  • Review web server and FreePBX logs for unauthenticated requests to Administrator endpoints, especially unusual parameters or SQL-like payloads.
  • Monitor database activity for unexpected schema changes, new admin users or bulk data reads.
  • Hunt for unexpected processes, web shells or outbound connections originating from the FreePBX host.
  • Alert on Administrator interface access from untrusted or external source IP addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-57819 to the Known Exploited Vulnerabilities catalog on 29 August 2025 as "Sangoma FreePBX Authentication Bypass Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 19 September 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-57819 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19006Sangoma FreePBX improper authentication allows remote admin bypassFreePBX versions 115.0.16.26, 14.0.13.11, 13.0.197.13 and below contain an incorrect access control flaw (CWE-287 improper authentication) that lets …KEVEPSS 56%analysed10.0CVE-2014-7235Freepbx code injection vulnerabilityhtdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.…EPSS 43%9.8CVE-2020-36630Sangoma freepbx sql injection vulnerabilityA vulnerability was found in FreePBX cdr 14.0. It has been classified as critical. This affects the function ajaxHandler of the file ucp/Cdr.class.ph…EPSS 0.68%9.3CVE-2026-46376Sangoma freepbx hard-coded credentials vulnerabilityFreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP)…EPSS 0.50%9.3CVE-2025-66039Sangoma freepbx improper authentication vulnerabilityFreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the a…EPSS 3.3%8.8CVE-2023-43336Sangoma freepbx improper access control vulnerabilitySangoma Technologies FreePBX before cdr 15.0.18, 16.0.40, 15.0.16, and 16.0.17 was discovered to contain an access control issue via a modified param…EPSS 0.72%8.7CVE-2024-58294Sangoma freepbx os command injection vulnerabilityFreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to ex…EPSS 3.6%8.6CVE-2026-28287Sangoma freepbx os command injection vulnerabilityFreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vu…EPSS 1.5%

Source: NIST National Vulnerability Database (record CVE-2025-57819), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.