{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/freepbx-15.x--15.0.66-16.x--16.0.89-17.x--17.0.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sangoma:freepbx:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2025-57819"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FreePBX (15.x \u003c 15.0.66, 16.x \u003c 16.0.89, 17.x \u003c 17.0.3)"],"_cs_severities":["critical"],"_cs_tags":["webapps","cve","rce","sql-injection","exploit"],"_cs_type":"advisory","_cs_vendors":["FreePBX"],"content_html":"\u003cp\u003eFreePBX is vulnerable to a critical unauthenticated remote code execution (RCE) vulnerability, tracked as CVE-2025-57819, affecting versions prior to 15.0.66, 16.0.89, and 17.0.3. The vulnerability resides in the Endpoint Manager module's 'brand' parameter within the '/admin/ajax.php' endpoint. Because the application fails to properly sanitize user input before incorporating it into SQL queries, an unauthenticated attacker can perform stacked SQL injection attacks. By leveraging this flaw, an attacker can insert arbitrary entries into the 'cron_jobs' table of the underlying database. These entries are periodically executed by the system's cron daemon with administrative privileges, typically as the Apache web server user, resulting in full remote code execution on the server. The availability of weaponized exploit code in the public domain necessitates immediate patching.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an internet-facing FreePBX server running a vulnerable version of the Endpoint Manager module.\u003c/li\u003e\n\u003cli\u003eThe attacker sends a crafted GET request to '/admin/ajax.php' targeting the 'brand' parameter.\u003c/li\u003e\n\u003cli\u003eThe crafted input performs SQL injection to bypass authentication or validation routines using stacked queries.\u003c/li\u003e\n\u003cli\u003eThe attacker executes a SQL 'INSERT' statement to add a new task to the 'cron_jobs' table.\u003c/li\u003e\n\u003cli\u003eThe injected command is configured as a reverse shell payload encoded in base64.\u003c/li\u003e\n\u003cli\u003eThe system's cron daemon processes the malicious entry within approximately 60 seconds.\u003c/li\u003e\n\u003cli\u003eThe system executes the base64-decoded bash command with the privileges of the web server user.\u003c/li\u003e\n\u003cli\u003eA reverse shell is established, granting the attacker interactive command execution on the host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2025-57819 leads to complete server compromise. As the malicious cron job executes with the privileges of the web server user, attackers can gain persistent access, exfiltrate sensitive configuration data, or pivot into the internal network where the FreePBX instance is hosted. This vulnerability is reported to be included in CISA's Known Exploited Vulnerabilities catalog.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePatch all affected FreePBX instances immediately: update to 15.0.66, 16.0.89, 17.0.3, or later versions.\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious requests to '/admin/ajax.php' containing SQL injection patterns.\u003c/li\u003e\n\u003cli\u003eAudit the 'cron_jobs' table in the FreePBX database for any unauthorized or suspicious command entries.\u003c/li\u003e\n\u003cli\u003eRestrict access to the FreePBX web management interface to trusted internal networks via firewall rules to mitigate exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-03T14:54:16Z","date_published":"2026-09-03T14:54:16Z","id":"https://feed.craftedsignal.io/briefs/2026-09-freepbx-rce/","summary":"An unauthenticated SQL injection vulnerability (CVE-2025-57819) in the FreePBX Endpoint Manager module allows attackers to achieve remote code execution by injecting malicious cron jobs.","title":"FreePBX Endpoint Manager Unauthenticated Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2026-09-freepbx-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - FreePBX (15.x \u003c 15.0.66, 16.x \u003c 16.0.89, 17.x \u003c 17.0.3)","version":"https://jsonfeed.org/version/1.1"}