CVE-2025-57819
KEVCRITICAL 10.0EPSS 88.3%
FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3.
- CVSS v4.0
- 10.0 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 88.27% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-08-29
- Nuclei
- critical
- Published
- 2025-08-28
- Updated
- 2026-02-26
Proof-of-concept exploits (22)
- MuhammadWaseem29/SQL-Injection-and-RCE_CVE-2025-578197★ · 2025-09-12
- blueisbeautiful/CVE-2025-578198★ · 2025-09-01
- brokendreamsclub/CVE-2025-578198★ · 2025-09-01
- orange0Mint/CVE-2025-57819_FreePBX2★ · 2025-09-18
- rxerium/CVE-2025-578191★ · 2025-10-14
- watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-5781929★ · 2025-09-08
- xV4nd3Rx/CVE-2025-57819_FreePBX-PoC1★ · 2025-09-24
- 0xEhab/FreePBX-CVE-2025-57819-RCE
- 0xyngtg/FreePBX-CVE-2025-57819-CVE-2025-61678
- Its1Zero/cve-2025-57819-exploit
- JazzTheRabbit/FreePBX-SQLi-RCE
- Jeanback1/CVE-2025-57819-exploit
- K3ysTr0K3R/CVE-2025-57819
- Neobee714/CVE-2025-57819-POC
- TeteREN/CVE-2025-57819-RCE
- YuvrajSHAD/FreePBX-CVE-2025-57819
- b4sh2/CVE-2025-57819-poc
- cybertechajju/cve-2025-57819
- jf-gondim/freepbx-endpoint-sqli-rce
- ozcanpng/CVE-2025-57819-FreePBX-RCE2Root
- Jeanback1/exploit-vault
- jasonbernier/CVE-2025-5781