← CVE Tracker
9.8CRITICALCISA KEV — actively exploited

CVE-2025-57819 — FreePBX is an open-source web-based graphical user interface.

Sangoma · Freepbx · Published 28 Aug 2025 · Modified 26 Sept 2026

Description

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

References

What to do
  1. Check whether Freepbx is in your asset inventory.
  2. Exploitation confirmed — patch within 72 hours.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-57819