Description
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
Exploits (13)
nomisec
WORKING POC
9 stars
by watchtowrlabs · remote
https://github.com/watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819
nomisec
WORKING POC
3 stars
by brokendreamsclub · infoleak
https://github.com/brokendreamsclub/CVE-2025-57819
nomisec
WORKING POC
1 stars
by xV4nd3Rx · infoleak
https://github.com/xV4nd3Rx/CVE-2025-57819_FreePBX-PoC
nomisec
WORKING POC
by MuhammadWaseem29 · infoleak
https://github.com/MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-57819
metasploit
WORKING POC
EXCELLENT
by Echo_Slow, Piotr Bazydlo, Sonny · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/freepbx_unauth_sqli_to_rce.rb
Nuclei Templates (1)
FreePBX - Remote Code Execution
CRITICALby watchtowr,pussycat0x,DhiyaneshDk
Shodan:
http.title:"freepbx" || http.favicon.hash:"-1908328911" || http.favicon.hash:"1574423538" || http.title:"freepbx administration"
FOFA:
icon_hash="-1908328911" || icon_hash="1574423538" || title="freepbx administration" || title="freepbx"
Scores
CVSS v3
9.8
EPSS
0.7673
EPSS Percentile
99.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+8 more repos
Details
CISA KEV
2025-08-29
VulnCheck KEV
2025-08-28
ENISA EUVD
EUVD-2025-26123
CWE
CWE-288
CWE-89
Status
published
Products (1)
sangoma/freepbx
15.0 - 15.0.66
Published
Aug 28, 2025
KEV Added
Aug 29, 2025
Tracked Since
Feb 18, 2026