Skip to content
COOEY

EXPOSURES › CVE-2025-57819

CVE-2025-57819

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-08-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-57819 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 90/100 rceexploited-in-wildunpatched

Sangoma FreePBX had unpatched RCE allowing unauth'd access to Admin leading to remote code execution

Sangoma FreePBX, a VoIP system, had a critical unpatched vulnerability that enabled remote attackers to execute arbitrary code without authentication, posing a severe security risk to DIB organizations using the product.

Shame score — Critical unpatched vulnerability enabling remote code execution without authentication

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.