SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-57819

Sangoma FreePBX Authentication Bypass Vulnerability

KEVCRITICAL 10.0EPSS 85.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 19 September 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

CVSS 4.0
10.0 CRITICALCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
EPSS
85.46% probability · 100th percentile
CISA KEV
Listed 29 August 2025 · due 19 September 2025
Weakness
CWE-89, CWE-288
Affected
sangoma/freepbx
Source
security-advisories@github.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h ; https://nvd.nist.gov/vuln/detail/CVE-2025-57819

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.