Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Sangoma Patches Critical Zero-Day Exploited to Hack FreePBX Servers

Tracked as CVE-2025-57819 (CVSS score of 10/10), the bug is described as an insufficient sanitization of user-supplied data.

Sangoma has released emergency patches for a zero-day vulnerability exploited to hack FreePBX servers with the administrator control panel accessible from the internet.

Tracked as CVE-2025-57819 (CVSS score of 10/10), the bug is described as an insufficient sanitization of user-supplied data. Successful exploitation of the flaw allows attackers to access the FreePBX administrator panel, enabling database manipulation and remote code execution (RCE).

Fixes were rolled out for FreePBX versions 15, 16, and 17, after Sangoma discovered that the security defect had been exploited in the wild starting on or before August 21. The hacked servers had inadequate IP filtering/ACLs, as noted in a GitHub advisory.

“This initial entry point was then chained with several other steps to ultimately gain potentially root level access on the target systems,” the advisory reads.

The issue was discovered in the commercial “endpoint” module. Users are advised to lock down all administrator access, remote internet access to the FreePBX servers, ensure the servers are protected by a firewall, update to a patched version, and check that the “endpoint” has the recommended fixes.

“Users should check their automated security updates are active. We are aware of a current issue in the v17 “framework” module that may prevent automated update notification emails,” Sangoma notes.

Advertisement. Scroll to continue reading.

Sangoma has released indicators-of-compromise (IOCs) to help administrators hunt for signs of exploitation, as well as recommended restoration steps.

On Friday, the US cybersecurity agency CISA added CVE-2025-57819 to its Known Exploited Vulnerabilities (KEV) catalog, urging federal agencies to patch it by September 19, as mandated by Binding Operational Directive (BOD) 22-01.

Although BOD 22-01 only applies to federal agencies, all organizations are advised to review CISA’s KEV list and take the necessary steps to mitigate the security defects it identifies.

Sangoma FreePBX is an open source interface for the management of Asterisk, a framework for real-time, multi-protocol communications applications.

Related: WhatsApp Zero-Day Exploited in Attacks Targeting Apple Users

Related: Citrix Patches Exploited NetScaler Zero-Day

Related: Organizations Warned of Exploited Git Vulnerability

Related:Hundreds of N-able N-central Instances Affected by Exploited Vulnerabilities

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.