CVE-2025-57819PoC(sangoma / freepbx)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (3 mentions)

Immediate actions

  • Prioritize remediation for sangoma freepbx systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.

7.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-09-19. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-89CWE-288

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

RISING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freepbx

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 19 mentions across 10 observed days
  • Momentum state: rising

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 7 signals
  • Technical details provided in 3 signals
  • General: 5 classified signals
  • Peaked 1d ago at 3 mentions (2026-10-01); latest day: 3
  • 19 total mentions across 10 days

Affected systems

Vendors
Products
freepbx

Deep dive

Activity timeline19 mentions / 10d
01223Mentions · 2026-03-12: 2Mentions · 2026-04-08: 1Mentions · 2026-06-09: 1Mentions · 2026-06-13: 1Mentions · 2026-08-29: 2Mentions · 2026-09-04: 2Mentions · 2026-09-08: 2Mentions · 2026-09-18: 2Mentions · 2026-10-01: 3Mentions · 2026-10-07: 3PoC Mentioned / Linked · 2026-03-12: 2PoC Mentioned / Linked · 2026-06-13: 1PoC Mentioned / Linked · 2026-08-29: 1PoC Mentioned / Linked · 2026-09-04: 1PoC Mentioned / Linked · 2026-09-08: 1PoC Mentioned / Linked · 2026-09-18: 1Exploit Tool / Code · 2026-03-12: 1Exploit Tool / Code · 2026-08-29: 1Exploit Tool / Code · 2026-09-04: 1Exploit Tool / Code · 2026-09-08: 1Exploit Tool / Code · 2026-09-18: 1Active Exploitation · 2026-04-08: 1Technical Details · 2026-03-12: 1Technical Details · 2026-06-13: 1Technical Details · 2026-09-04: 103-1204-0806-0906-1308-2909-0409-0809-1810-0110-07
Signal classification4 categories
PoC
646.2%
General
538.5%
Active Exploitation
17.7%
Exploit
17.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-122
PoC2
2026-04-081
Active Exploitation1
2026-06-091
General1
2026-06-131
PoC1
2026-08-292
General1PoC1
2026-09-042
General1PoC1
2026-09-082
General1PoC1
2026-09-182
Exploit1General1
Full discourse19 posts
  • 0xor0ne@0xor0ne
    PoC

    Exploiting FreePBX via unauthenticated SQL injection (CVE-2025-57819) Research by @watchtowrcyber: https://labs.watchtowr.com/you-already-have-our-personal-data-take-our-phone-calls-too-freepbx-cve-2025-57819/ #cybersecurity https://t.co/Pv0Th0ItxB

    Post summary

    The post references research on an unauthenticated SQL injection in FreePBX (CVE‑2025‑57819) and links to a blog that likely contains a proof of concept.

    110178315.0K
    88.5K followersView on X
  • Team Cymru Research@teamcymru_S2
    Active Exploitation

    🚨 Top 25 CVE Exploitation Attempts - Team Cymru - S2 (Ranked by unique source IPs over 14 days) 1. CVE-2025-0282 · Ivanti Connect Secure 2. CVE-2025-49706 · SharePoint 3. CVE-2020-3452 · Cisco ASA 4. CVE-2025-61884 · Oracle EBS 5. CVE-2024-32113 · Apache OFBiz 6. CVE-2025-53770 · SharePoint 7. CVE-2025-24893 · XWiki 8. CVE-2025-61882 · Oracle EBS 9. CVE-2025-5777 · Citrix NetScaler 10. CVE-2025-34028 · Commvault 11. CVE-2024-57727 · SimpleHelp 12. CVE-2025-20362 · Cisco ASA/FTD 13. CVE-2024-1212 · Kemp LoadMaster 14. CVE-2024-38856 · Apache OFBiz 15. CVE-2022-40684 · Fortinet 16. CVE-2024-9465 · Palo Alto Expedition 17. CVE-2025-11371 · Gladinet CentreStack 18. CVE-2025-58360 · GeoServer 19. CVE-2025-57819 · FreePBX 20. CVE-2025-31324 · SAP NetWeaver 21. CVE-2024-7593 · Ivanti vTM 22. CVE-2025-31125 · Vite Dev Server 23. CVE-2025-64446 · FortiWeb 24. CVE-2024-12987 · DrayTek Vigor 25. CVE-2018-7600 · Drupal

    Post summary

    Team Cymru’s report indicates that the listed CVEs were targeted in exploitation attempts over a 14‑day period, signifying active attacks.

    070921.2K
    5.5K followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-57819 (CVSS: 10) FreePBX CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-40281 (CVSS: 10) gotenberg CVE-2024-40453 (CVSS: 9.8) CVE-2026-39987 (CVSS: 9.3) marimo-team ..🧵👇

    11071347
    377 followersView on X
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-57819 (CVSS: 10) FreePBX CVE-2026-49869 (CVSS: 10) kestra-io CVE-2026-38526 (CVSS: 9.9) CVE-2021-43716 (CVSS: 9.8) CVE-2021-43717 (CVSS: 9.8) ..🧵👇

    10062554
    377 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2025-32432 CVE-2025-57819 CVE-2026-48908 CVE-2026-76460 CVE-2026-85706 ..🧵👇

    Post summary

    The text only lists several CVE identifiers without providing PoC links, exploit details, active exploitation claims, remediation information, or technical vulnerability details.

    21030121
    47 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2025-57819 [CRITICAL/PoC] CVSS: 10 | Vendor: #FreePBX FreePBX-Breaker 🔗 https://exploitgrid.net/exploits/6f819e4a-d72f-48ad-8e63-8311a1b274ed

    1001071
    377 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2025-57819 — FreePBX · PoC live ├ CVE-2026-49869 — Kestra · PoC live ├ CVE-2026-38526 (9.9) · PoC live └ CVE-2021-43716 · CVE-2021-43717 (9.8) · PoC live

    1001051
    374 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2025-57819 [CRITICAL/PoC] CVSS: 10 | Vendor: #FreePBX cve-2025-57819 🔗 https://exploitgrid.net/exploits/8bba6fc0-2a29-4ec1-913b-e0ab99ee4c07

    10010104
    374 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2025-57819 — FreePBX ("FreePBX-Breaker") · PoC live ├ CVE-2026-105134 — Ahsay · PoC live ├ CVE-2026-40281 (Gotenberg) · still unpatched, PoC live again ├ CVE-2024-40453 · PoC live (9.8) └ CVE-2026-39987 — marimo · RCE PoC live (9.3)

    1000047
    377 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2025-57819 [CRITICAL/PoC] cve-2025-57819-freepbx-range 🔗 https://exploitgrid.net/exploits/e7e60cf7-c847-4649-b434-d80a5d5d5fd2

    Post summary

    The post references CVE‑2025‑57819 and supplies a link to an exploit grid entry, confirming a PoC is available. While an exploit resource is cited, there is no indication of active real‑world exploitation, patches, or workarounds.

    1000041
    47 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-mlbER4p [CRITICAL/PoC] Linked: CVE-2025-57819 CVE-2025-57819 🔗 https://exploitgrid.net/exploits/15451ad1-bbb6-4931-a450-02b90ca20e4c

    Post summary

    A proof‑of‑concept exploit for CVE‑2025‑57819 is available on ExploitGrid, marked as critical severity. No active exploitation or mitigation details are provided.

    1000047
    41 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2024-3094 CVE-2025-31324 CVE-2025-55182 CVE-2025-57819 CVE-2026-28576 ..🧵👇

    Post summary

    The post is a concise threat digest that lists several newly disclosed critical CVEs but provides no further technical, exploit, or patch information.

    1000051
    41 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-EDB-tcieyJw [CRITICAL/PoC] Linked: CVE-2025-57819 FreePBX 17.0.2 - Remote Code Execution (RCE) 🔗 https://exploitgrid.net/exploits/419ec296-40e5-4b5c-92a4-79577c8b9b94

    Post summary

    A PoC and ready‑to‑use exploit for the FreePBX 17.0.2 RCE vulnerability (CVE‑2025‑57819) has been published on ExploitGrid, but no patch info or active exploitation reports are mentioned.

    1000059
    40 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2025-57819 CVE-2026-83548 CVE-2026-59827 CVE-2017-5638 CVE-2025-32958 ..🧵👇

    Post summary

    The digest simply enumerates several CVE identifiers without providing additional context, details, or actionable information.

    1000067
    40 followersView on X
  • ExploitGrid@exploitgrid
    PoC

    [EXPLOIT] EGE-GH-sePCXJa [CRITICAL/PoC] Linked: CVE-2025-57819 htb-labs-connected 🔗 https://exploitgrid.net/exploits/9c929cd2-4af7-48b3-bce3-ea4d0246c36d

    Post summary

    A proof‑of‑concept exploit for CVE‑2025‑57819 has been posted with a link to the exploit code, but no active exploitation, patch, or detailed technical description is provided.

    1000040
    38 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: CVE-2026-46339 CVE-2024-45798 CVE-2025-55182 CVE-2025-57819 CVE-2025-59528 ..🧵👇

    Post summary

    The tweet lists five critical CVEs disclosed today but provides no additional technical, exploit, or mitigation information.

    1000071
    38 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    PoC

    🚨 FreePBX 0-Day to Root: How a Single SQL Injection Unlocks Full System Compromise on HTB’s Connected (#CVE-2025-57819) https://undercodetesting.com/freepbx-0-day-to-root-how-a-single-sql-injection-unlocks-full-system-compromise-on-htbs-connected-cve-2025-57819/ Educational Purposes!

    Post summary

    A new FreePBX 0-Day (CVE-2025-57819) is disclosed, with a single SQL injection enabling full root compromise; the linked article likely contains a PoC and technical details, but no patch or active exploitation info is provided.

    0000028
    607 followersView on X
  • Loginsoft Threat Intel@Loginsoft_Intel
    General

    Cytellite recent detection targeting CVE-2025-57819 — Alsycon B.V. Visit -- https://cti.loginsoft.com/ip/45.81.23.7 #Loginsoft #Cytellite #Cybersecurity #CVE202557819 #LOVI #ThreatIntelligence #Infosecurity #AI https://t.co/xi00Ne2WnJ

    Post summary

    The post announces a recent detection of CVE‑2025‑57819 but offers no concrete evidence of exploitation or detailed technical information.

    0000041
    22 followersView on X
  • Smurfs ✘@0xsmurfsr
    PoC

    เผื่อใครอยากได้ PoC ไว้ลองเล่นๆ https://github.com/brokendreamsclub/CVE-2025-57819

    Post summary

    The post shares a PoC for CVE‑2025‑57819 via a GitHub link, confirming availability of proof‑of‑concept code but no details on active exploitation or technical specifics.

    00000210
    426 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomafreepbx---

Explore more