---
id: CVE-2025-67722
title: >-
  FreePBX is an open-source web-based graphical user interface (GUI) that
  manages Asterisk
summary: >-
  FreePBX is an open-source web-based graphical user interface (GUI) that
  manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX
  framework, an authenticated local privilege escalation exists in the
  deprecated FreePBX startu…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-426
vendor: sangoma
product: freepbx
affected:
  - 'freepbx >= 16.0, < 16.0.45'
  - 'freepbx >= 17.0, < 17.0.24'
patched:
  - freepbx 17.0.24
published: '2025-12-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67722'
references:
  - url: >-
      https://github.com/FreePBX/security-reporting/security/advisories/GHSA-p42w-v77m-hfp8
    label: security-advisories@github.com
  - url: 'https://www.freepbx.org/watch-what-we-do-with-security-fixes-%f0%9f%91%80'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00128
epssPercentile: 0.02116
ingestedAt: '2026-10-07T20:46:46.944Z'
---

## Overview

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated `amportal` utility, the lookup for the `freepbx_engine` file occurs in `/etc/asterisk/` directories. Typically, these are configured by FreePBX as writable by the **asterisk** user and any members of the **asterisk** group. This means that a member of the **asterisk** group can add their own `freepbx_engine` file in `/etc/asterisk/` and upon `amportal` executing, it would exec that file with root permissions (even though the file was created and placed by a non-root user). Version 16.0.45 and 17.0.24 contain a fix for the issue. Other mitigation strategies are also available. Confirm only trusted local OS system users are members of the `asterisk` group. Look for suspicious files in the `/etc/asterisk/` directory (via Admin -> Config Edit in the GUI, or via CLI). Double-check that `live_dangerously = no` is set (or unconfigured, as the default is **no**) in `/etc/asterisk/asterisk.conf` file. Eliminate any unsafe custom use of Asterisk dial plan applications and functions that potentially can manipulate the file system, e.g., System(), FILE(), etc.

## Affected

- `freepbx >= 16.0, < 16.0.45`
- `freepbx >= 17.0, < 17.0.24`

## Remediation

Upgrade past the affected range:

- `freepbx 17.0.24`
