Advisory 97

Advisory 97: CVE-2025-57819_Sangoma FreePBX Authentication Bypass Vulnerability

Release Date: 29th of August 2025

Impact : HIGH / CRITICAL

TLP Rating: Clear

CERT Vanuatu (CERTVU) and the Department of Communication and Digital Transformation (DCDT) provide the following advisory.

This alert is relevant to Organizations and technical individuals who utilize and manage the product.

What is it?

CERTVU would like to advise on the following;

CVE-2025-57819 is a critical vulnerability in the commercial “endpoint” module of FreePBX versions 15, 16, and 17, caused by insufficient sanitization of user-supplied input. This flaw enables unauthenticated attackers to bypass admin access controls, perform SQL injection, and ultimately achieve remote code execution

 

References

  1. https://www.cisa.gov/news-events/alerts/2025/08/29/cisa-adds-one-known-exploited-vulnerability-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2025-57819
  3. https://nvd.nist.gov/vuln/detail/CVE-2025-57819