EXPOSURES › CVE-2025-57819
CVE-2025-57819
HIGH ⌖ ON CISA KEV · EXPLOITEDSangoma FreePBX had unpatched RCE allowing unauth'd access to Admin leading to remote code execution
Sangoma FreePBX, a VoIP system, had a critical unpatched vulnerability that enabled remote attackers to execute arbitrary code without authentication, posing a severe security risk to DIB organizations using the product.
Shame score — Critical unpatched vulnerability enabling remote code execution without authentication
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Sangoma FreePBX contains an authentication bypass vulnerability due to insufficiently sanitized user-supplied data allows unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution.