CVE-2025-57819

Sangoma FreePBX Authentication Bypass Vulnerability

10.0
CVSS 4.0
85.5 %
EPSS (current)
2025-08-29
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Sangoma / FreePBX

Published: 2025-08-28 · Due (CISA): 2025-09-19

CWE: CWE-89 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
nucleihttp/cves/2025/CVE-2025-57819.yamlFreePBX - Remote Code Execution–
metasploitexploit/unix/http/freepbx_unauth_sqli_to_rceexploit/unix/http/freepbx_unauth_sqli_to_rce2025-08-28
exploitdb52681FreePBX 17.0.2 - Remote Code Execution (RCE)2026-09-03

References only — no downloads or instructions.

Sources