critical Known exploitedREV. 01
CVE-2025-57819Sangoma FreePBX — unsanitised input opens the administrator
FreePBX 15, 16 and 17 do not sanitise user input on some endpoints, which lets an unauthenticated attacker reach the administrator interface, manipulate the database and run code on the telephony server.
Read the risk
THE VITAL STATS- CVSS score
- 9.8/ 10 CVSS v3.1
- EPSS probability
- 85% Likelihood of exploitation
- Attack complexity
- Low Conditions needed to exploit
- Known exploited
- Yes — CISA KEV
- CVE published
- 2025-08-28
- Added to KEV
- 2025-08-29
- Exploit published
- Yes
- Confidence
- high
- Kill chain
- initial access
- MITRE ATT&CK
- T1190
- Severity
- critical
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attacker needsNetwork access to the FreePBX endpoints; no credentials needed.
Behind the card
5 REFERENCES- 01CVE recordNVD recordnvd.nist.gov
- 02CISACISA Known Exploited Vulnerabilities catalogcisa.gov
- 03Vendor advisorycommunity.freepbx.orgcommunity.freepbx.org
- 04Vendor advisorygithub.comgithub.com
- 05Exploitgithub.comgithub.com
Field-level provenanceTRACE THE SOURCES +
Which source supports each field, when it was retrieved, and who extracted it.
| Fields | Source | Retrieved | Extractor | Confidence |
|---|---|---|---|---|
| cvss, exploitation.attack_complexity, exploitation.exploit_available, references, published_at | nvd.nist.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| exploitation.known_exploited, exploitation.kev_added | cisa.gov | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| epss | api.first.org | 2026-09-24 | scrty-crds-pipeline/0.1 | high |
| title, summary, severity, remediation, mitre_attack, kill_chain, recommended_action, confidence, tags, exploitation.prerequisites | nvd.nist.gov | 2026-09-24 | claude-code | high |
Printing history
THE RECORD- r1Initial base card
First printing. This card has not been reprinted since publication.