Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available

FreePBX Servers Targeted by Zero-Day Flaw, Emergency Patch Now Available

Posted on August 29, 2025August 29, 2025 By CWS

Aug 29, 2025Ravie LakshmananZero-Day / Vulnerability
The Sangoma FreePBX Safety Staff has issued an advisory warning about an actively exploited FreePBX zero-day vulnerability that impacts programs with an administrator management panel (ACP) uncovered to the general public web.
FreePBX is an open-source non-public department change (PBX) platform broadly utilized by companies, name facilities, and repair suppliers to handle voice communications. It is constructed on prime of Asterisk, an open-source communication server.
The vulnerability, assigned the CVE identifier CVE-2025-57819, carries a CVSS rating of 10.0, indicating most severity.
“Insufficiently sanitized user-supplied knowledge permits unauthenticated entry to FreePBX Administrator, resulting in arbitrary database manipulation and distant code execution,” the undertaking maintainers stated in an advisory.
The problem impacts the next variations –

FreePBX 15 prior to fifteen.0.66
FreePBX 16 previous to 16.0.89, and
FreePBX 17 previous to 17.0.3

Sangoma stated an unauthorized consumer started accessing a number of FreePBX model 16 and 17 programs related to the web beginning on or earlier than August 21, 2025, particularly people who have insufficient IP filtering or entry management lists (ACLs), by profiting from a sanitization challenge within the processing of user-supplied enter to the industrial “endpoint” module.

The preliminary entry obtained utilizing this technique was then mixed with different steps to doubtlessly achieve root-level entry on the goal hosts, it added.
In mild of lively exploitation, customers are suggested to improve to the newest supported variations of FreePBX and limit public entry to the administrator management panel. Customers are additionally suggested to scan their environments for the next indicators of compromise (IoCs) –

File “/and so on/freepbx.conf” just lately modified or lacking
Presence of the file “/var/www/html/.clear.sh” (this file mustn’t exist on regular programs)
Suspicious POST requests to “modular.php” in Apache internet server logs relationship again to no less than August 21, 2025
Telephone calls positioned to extension 9998 in Asterisk name logs and CDRs are uncommon (until beforehand configured)
Suspicious “ampuser” consumer within the ampusers database desk or different unknown customers

“We’re seeing lively exploitation of FreePBX within the wild with exercise traced again so far as August 21 and backdoors being dropped post-compromise,” watchTowr CEO Benjamin Harris stated in a press release shared with The Hacker Information.
“Whereas it is early, FreePBX (and different PBX platforms) have lengthy been a favourite looking floor for ransomware gangs, preliminary entry brokers and fraud teams abusing premium billing. If you happen to use FreePBX with an endpoint module, assume compromise. Disconnect programs instantly. Delays will solely enhance the blast radius.”

The Hacker News Tags:Emergency, Flaw, FreePBX, Patch, Servers, Targeted, ZeroDay

Post navigation

Previous Post: How Adversary-In-The-Middle (AiTM) Attack Bypasses MFA and EDR?
Next Post: Click Studios Patches Passwordstate Authentication Bypass Vulnerability in Emergency Access Page

Related Posts

Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data Rogue NuGet Package Poses as Tracer.Fody, Steals Cryptocurrency Wallet Data The Hacker News
North Korean Hackers Exploit VS Code for New Malware North Korean Hackers Exploit VS Code for New Malware The Hacker News
Security Flaws in AI Frameworks Expose Sensitive Data Security Flaws in AI Frameworks Expose Sensitive Data The Hacker News
Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login Palo Alto Fixes GlobalProtect DoS Flaw That Can Crash Firewalls Without Login The Hacker News
GitHub Enhances Security by Blocking Risky Pwn Requests GitHub Enhances Security by Blocking Risky Pwn Requests The Hacker News
Are Forgotten AD Service Accounts Leaving You at Risk? Are Forgotten AD Service Accounts Leaving You at Risk? The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark