Back to overview

CVE-2025-57819

CRITICAL KEV CISA Exploitation: ACTIVE
10.0
CVSS 4.0
Description
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

Metadata

CVE ID
CVE-2025-57819
State
PUBLISHED
Assigner
GitHub_M
Reserved
2025-08-20 14:30 UTC
Published
2025-08-28 16:45 UTC
Last updated
2026-02-26 17:47 UTC
Primary CWE
CWE-89
CWE-89: Improper Neutralization of Special Elements used in …
Vendor / Product
FreePBX / endpoint
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
SSVC — CISA Coordinator
Exploitation
ACTIVE
Automatable
yes
Tech. Impact
total
CISA Known Exploited Vulnerability
Vulnerability name
Sangoma FreePBX Authentication Bypass Vulnerability
Vendor
Sangoma
Product
FreePBX
Added to KEV
2025-08-29
Due date
2025-09-19
Ransomware
Not known
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
CISA description
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.
Affected products (1)
VendorProductPlatformVersions
FreePBX endpoint < 15.0.66, < 16.0.89, < 17.0.3
Weakness (CWE)
CWESourceDescription
CWE-288 cna CWE-288: Authentication Bypass Using an Alternate Path or Channel
CWE-89 cna CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
References (2)
Back to overview