CVE-2025-57819

FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE

Basic Information

CVE State
PUBLISHED
Reserved Date
August 20, 2025
Published Date
August 28, 2025
Last Updated
February 26, 2026
Vendor
FreePBX
Product
endpoint
Description
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
Tags
cisa nuclei_scanner

CVSS Scores

CVSS v4.0

10.0 - CRITICAL

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

SSVC Information

Exploitation
active
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:39:48 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:39:48 UTC

Scanner Integrations

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nuclei