Vulnerability in Asterisk Affects Command Line Permission Settings
CVE-2025-47780
What is CVE-2025-47780?
A vulnerability has been identified in the Asterisk PBX that improperly handles command line permissions. Administrators relying on the cli_permissions.conf configuration to restrict shell commands may find that their settings do not function as intended. This oversight could allow unauthorized command execution, posing significant security risks. Users are advised to update to Asterisk versions 18.26.2, 20.14.1, 21.9.1, 22.4.1, as well as certified-asterisk versions 18.9-cert14 and 20.7-cert5 to mitigate this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
asterisk < 18.9-cert14 < 18.9-cert14
asterisk >= 18.10, < 18.26.2 < 18.10, 18.26.2
asterisk >= 20.0, < 20.7-cert5 < 20.0, 20.7-cert5
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
