CVE-2025-67722High· 7.8▾ TwilightFreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startu…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script amportal. In the deprecated amportal utility, the lookup for the freepbx_engine file occurs in /etc/asterisk/ directories. Typically, these are configured by FreePBX as writable by the asterisk user and any members of the asterisk group. This means that a member of the asterisk group can add their own freepbx_engine file in /etc/asterisk/ and upon amportal executing, it would exec that file with root permissions (even though the file was created and placed by a non-root user). Version 16.0.45 and 17.0.24 contain a fix for the issue. Other mitigation strategies are also available. Confirm only trusted local OS system users are members of the asterisk group. Look for suspicious files in the /etc/asterisk/ directory (via Admin -> Config Edit in the GUI, or via CLI). Double-check that live_dangerously = no is set (or unconfigured, as the default is no) in /etc/asterisk/asterisk.conf file. Eliminate any unsafe custom use of Asterisk dial plan applications and functions that potentially can manipulate the file system, e.g., System(), FILE(), etc.
freepbx >= 16.0, < 16.0.45freepbx >= 17.0, < 17.0.24Upgrade past the affected range:
freepbx 17.0.24Connected by shared product, vendor, weakness, or advisory.
CVE-2025-67736High· 7.2The FreePBX module tts (Text to Speech) for FreePBX, an open-source web-based graphical user interface (GUI) that manages Asterisk
CVE-2025-66039Critical· 9.8FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems
CVE-2025-57819Critical· 9.8FreePBX is an open-source web-based graphical user interface
CVE-2026-9586Critical· 9.8An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into …
CVE-2022-37325High· 7.5In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
CVE-2025-43079Medium· 6.3The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported versions that invoked multiple system commands without using absolute paths and without sanitizing the $PATH environmen…