Skip to content
COOEY

FAIL › dossier

Sangoma

VENDOR

· dossier confidence 50%

PROFILE
CategoryTelecommunicationsWhat they doSangoma provides hardware and software for voice and data communication.
SECURITY POSTURE

Vulnerabilities have been identified and addressed through patching and security training.

Notable failures
  • CVE-2025-57819: High [RCE] in Sangoma FreePBX allowing unauthenticated access to Admin leading to remote code execution
  • CVE-2025-64328: High [RCE] in Sangoma FreePBX OS Command Injection Vulnerability exploited post-authentication
  • CVE-2019-19006: High [RCE] in Sangoma FreePBX exposed to unauthorized access due to improper authentication
  • CVE-2026-46376: Critical issue in FreePBX from versions 15.0.42 to before 16.0.45 and 17.0.7
Patterns: Repeated unpatched edge-device RCEs; Post-authentication OS command injection vulnerabilities; Improper authentication leading to unauthorized access
FAILURE HISTORY · 4
DATEEVENTSEVSUMMARY
2025-08-29 CVE-2025-57819 high Sangoma FreePBX had unpatched RCE allowing unauth'd access to Admin leading to remote code execution
2026-02-03 CVE-2025-64328 high Sangoma FreePBX OS Command Injection Vulnerability exploited post-authentication
2026-02-03 CVE-2019-19006 high Sangoma FreePBX exposed to unauthorized access due to improper authentication
2026-05-29 CVE-2026-46376 critical CVE-2026-46376: FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, una
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:43:18.372665+00:00