PT-2025-35106 · Freepbx · Freepbx

Matthewljensen

·

Published

2025-08-28

·

Updated

2026-06-13

·

CVE-2025-57819

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions FreePBX versions prior to 15.0.66 FreePBX versions prior to 16.0.89 FreePBX versions prior to 17.0.3
Description FreePBX is an open-source web-based graphical user interface. A critical issue exists in the "endpoint" module where insufficiently sanitized user-supplied data allows unauthenticated attackers to bypass authentication controls. This flaw enables an attacker to perform SQL injection, which is a technique used to manipulate database queries, leading to arbitrary database manipulation and remote code execution with SYSTEM-level privileges. There are reports of this issue being actively exploited in the wild.
Recommendations Update to version 15.0.66 for FreePBX 15. Update to version 16.0.89 for FreePBX 16. Update to version 17.0.3 for FreePBX 17. As a temporary workaround, restrict access to the "endpoint" module to minimize the risk of exploitation.

Exploit

Fix

RCE

Authentication Bypass Using an Alternate Path or Channel

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-10524
CVE-2025-57819
GHSA-M42G-XG4C-5F3H

Affected Products

Freepbx