Unauthenticated Access Vulnerability in FreePBX by Sangoma Technologies
CVE-2025-57819

10CRITICAL

Key Information:

Vendor

Freepbx

Vendor
CVE Published:
28 August 2025

What is CVE-2025-57819?

FreePBX, an open-source web-based GUI, suffers from a vulnerability that permits unauthenticated users to gain access to the FreePBX Administrator interface. This is primarily due to insufficient sanitization of user-provided data. The flaw can lead to unauthorized database manipulation and may allow remote code execution, posing a significant risk to affected systems. Patches have been provided in versions 15.0.66, 16.0.89, and 17.0.3 to mitigate this vulnerability. Users are advised to upgrade to these versions to protect their systems.

Affected Version(s)

security-reporting < 15.0.66 < 15.0.66

security-reporting < 16.0.89 < 16.0.89

security-reporting < 17.0.3 < 17.0.3

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-57819 : Unauthenticated Access Vulnerability in FreePBX by Sangoma Technologies