PT-2025-35106 · Freepbx · Freepbx

·

CVE-2025-57819

·

Published

2025-08-28

·

Updated

2026-09-08

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FreePBX versions prior to 15.0.66 FreePBX versions prior to 16.0.89 FreePBX versions prior to 17.0.3
Description FreePBX is an open-source web-based graphical user interface for IP telephony systems. A critical issue exists in the endpoint module where insufficiently sanitized user-supplied data allows unauthenticated attackers to bypass authentication controls. This flaw can be chained with SQL injection—a technique where malicious SQL statements are inserted into entry fields for execution—to perform arbitrary database manipulation and achieve remote code execution with SYSTEM-level privileges. There are reports of this issue being actively exploited in the wild.
Recommendations Update FreePBX version 15 to 15.0.66 or later. Update FreePBX version 16 to 16.0.89 or later. Update FreePBX version 17 to 17.0.3 or later. As a temporary mitigation, restrict access to the endpoint module to minimize the risk of exploitation.

Exploit

Fix

RCE

SQL injection

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10524
CVE-2025-57819
GHSA-M42G-XG4C-5F3H

Affected Products

Freepbx