PT-2025-35106 · Freepbx · Freepbx
Matthewljensen
·
Published
2025-08-28
·
Updated
2026-06-13
·
CVE-2025-57819
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
FreePBX versions prior to 15.0.66
FreePBX versions prior to 16.0.89
FreePBX versions prior to 17.0.3
Description
FreePBX is an open-source web-based graphical user interface. A critical issue exists in the "endpoint" module where insufficiently sanitized user-supplied data allows unauthenticated attackers to bypass authentication controls. This flaw enables an attacker to perform SQL injection, which is a technique used to manipulate database queries, leading to arbitrary database manipulation and remote code execution with SYSTEM-level privileges. There are reports of this issue being actively exploited in the wild.
Recommendations
Update to version 15.0.66 for FreePBX 15.
Update to version 16.0.89 for FreePBX 16.
Update to version 17.0.3 for FreePBX 17.
As a temporary workaround, restrict access to the "endpoint" module to minimize the risk of exploitation.
Exploit
Fix
RCE
Authentication Bypass Using an Alternate Path or Channel
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freepbx