CVE-2025-57819

CRITICAL KEV NUCLEI LAB

Sangoma Freepbx < 15.0.66 - SQL Injection

Title source: rule

Description

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

Exploits (13)

nomisec WORKING POC 9 stars
by watchtowrlabs · remote
https://github.com/watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819
nomisec WRITEUP 6 stars
by cybertechajju · poc
https://github.com/cybertechajju/cve-2025-57819
nomisec WORKING POC 3 stars
by brokendreamsclub · infoleak
https://github.com/brokendreamsclub/CVE-2025-57819
nomisec SCANNER 1 stars
by rxerium · poc
https://github.com/rxerium/CVE-2025-57819
nomisec WORKING POC 1 stars
by xV4nd3Rx · infoleak
https://github.com/xV4nd3Rx/CVE-2025-57819_FreePBX-PoC
nomisec WORKING POC 1 stars
by ImBIOS · remote
https://github.com/ImBIOS/lab-cve-2025-57819
nomisec WRITEUP 1 stars
by net-hex · poc
https://github.com/net-hex/CVE-2025-57819
nomisec WORKING POC
by orange0Mint · remote
https://github.com/orange0Mint/CVE-2025-57819_FreePBX
nomisec WORKING POC
by MuhammadWaseem29 · infoleak
https://github.com/MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-57819
nomisec SCANNER
by Sucuri-Labs · poc
https://github.com/Sucuri-Labs/CVE-2025-57819-ioc-check
metasploit WORKING POC EXCELLENT
by Echo_Slow, Piotr Bazydlo, Sonny · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/freepbx_unauth_sqli_to_rce.rb

Nuclei Templates (1)

FreePBX - Remote Code Execution
CRITICALby watchtowr,pussycat0x,DhiyaneshDk
Shodan: http.title:"freepbx" || http.favicon.hash:"-1908328911" || http.favicon.hash:"1574423538" || http.title:"freepbx administration"
FOFA: icon_hash="-1908328911" || icon_hash="1574423538" || title="freepbx administration" || title="freepbx"

Scores

CVSS v3 9.8
EPSS 0.7673
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2025-08-29
VulnCheck KEV 2025-08-28
ENISA EUVD EUVD-2025-26123
CWE
CWE-288 CWE-89
Status published
Products (1)
sangoma/freepbx 15.0 - 15.0.66
Published Aug 28, 2025
KEV Added Aug 29, 2025
Tracked Since Feb 18, 2026