PROFILE
CategoryTelecommunicationsWhat they doSangoma provides hardware and software for voice and data communication.
SECURITY POSTURE
Vulnerabilities have been identified and addressed through patching and security training.
Notable failures
- CVE-2025-57819: High [RCE] in Sangoma FreePBX allowing unauthenticated access to Admin leading to remote code execution
- CVE-2025-64328: High [RCE] in Sangoma FreePBX OS Command Injection Vulnerability exploited post-authentication
- CVE-2019-19006: High [RCE] in Sangoma FreePBX exposed to unauthorized access due to improper authentication
- CVE-2026-46376: Critical issue in FreePBX from versions 15.0.42 to before 16.0.45 and 17.0.7
Patterns: Repeated unpatched edge-device RCEs; Post-authentication OS command injection vulnerabilities; Improper authentication leading to unauthorized access
FAILURE HISTORY · 4
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2025-08-29 | CVE-2025-57819 | high | Sangoma FreePBX had unpatched RCE allowing unauth'd access to Admin leading to remote code execution |
| 2026-02-03 | CVE-2025-64328 | high | Sangoma FreePBX OS Command Injection Vulnerability exploited post-authentication |
| 2026-02-03 | CVE-2019-19006 | high | Sangoma FreePBX exposed to unauthorized access due to improper authentication |
| 2026-05-29 | CVE-2026-46376 | critical | CVE-2026-46376: FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, una |
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-26 03:43:18.372665+00:00