FreePBX is an open-source web-based graphical interface for controlling and managing Asterisk. It allows organizations with fewer technical skills or resources to utilize Asterisk. CVE-2025-57819 is a critical zero-day vulnerability affecting versions 15, 16, and 17 of Sangoma FreePBX, specifically the endpoints module in versions prior to 15.0.66, 16.0.89, and 17.0.3. The assigned CVSS v4 score is 10.0 (Critical), reflecting the maximum level of exploitability and impact.
| Product | Sangoma FreePBX |
| Date | 2025-09-09 13:14:37 |
Technical Summary
The vulnerability originates from insufficient sanitization of user-supplied input within the FreePBX commercial endpoint module. This flaw allows unauthenticated attackers to bypass authentication mechanisms, gaining access to the FreePBX administration interface and arbitrarily manipulating the underlying database. Such access can be combined with further exploits to achieve remote code execution (RCE), leading to a total system compromise.
FreePBX provides a web interface for managing VoIP actions, such as creating extensions, modifying call routes, or installing and removing modules.
When an action is performed via the endpoints module, it is sent to modular.php running on a central FreePBX server, which translates it into SQL queries.
In normal operation, i.e., when requests are sent via the web interface, the requests are properly sanitized; however, sending requests directly to modular.php bypasses the sanitization layer.
This means an attacker can construct malformed HTTP requests containing malicious payloads that are passed into SQL queries without sanitization.
By exploiting this vulnerability, the attacker can manipulate the database logic, achieving SQL injection and, ultimately, authentication bypass.
Recommendations
- Immediate Patching: Update the endpoint module to:
- FreePBX 15 โ 15.0.66
- FreePBX 16 โ 16.0.89
- FreePBX 17 โ 17.0.3
- Isolate or Restrict Access: Enable firewalls if not already present and prohibit access to web management interfaces from the Internet/external zones.
- Scan for Indicators of Compromise (IoC): Check for signs of compromise, including:
- Modified or missing
/etc/freepbx.conffile - Presence of a suspicious script
/var/www/html/.clean.sh - Check Apache logs for POST requests to modular.php; dating back at least to August 21
- Check Asterisk logs for calls to extension 999; dating back at least to August 21
- Examine MariaDB/MySQL logs and tables for unknown MACD user entries in the ampusers table; specifically for a suspicious username
ampuser
- Modified or missing
Protect your organisation with Threat Intelligence and Digital Risk Protection.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
