FreePBX remediated CVE-2025-57819, an insufficient input-validation vulnerability affecting FreePBX versions 15, 16, and 17. The flaw can let an attacker gain unauthorized access and potentially execute arbitrary code on affected PBX systems.
FreePBX reported active exploitation against multiple version 16 and 17 deployments with internet-exposed management interfaces, particularly where IP filtering and access-control lists (ACLs) were inadequate. Organizations should apply the vendor security updates, confirm the Endpoint module is at the required patched version, restrict administrator interfaces to trusted networks, and investigate exposed systems using FreePBX-provided indicators of compromise.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
FreePBX reported active exploitation affecting multiple internet-exposed version 16 and 17 systems with insufficient IP filtering and access-control lists on their management interfaces.
FreePBX remediated CVE-2025-57819 in versions 15, 16, and 17 by releasing security updates. The insufficient input-validation flaw can permit unauthorized access and potentially arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
ncsc.nl
Open sourcecommunity.freepbx.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.