LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-64328: Sangoma FreePBX OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 3, 2026
CVSS 8.6 · High⚠ Actively exploited (CISA KEV)
8.6
CVSS score
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 24, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-64328 to its Known Exploited Vulnerabilities catalog on Feb 3, 2026, with a federal patch deadline of Feb 24, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection -> check_ssh_connect() function. An attacker can leverage this vulnerability to obtain remote access to the system as an asterisk user. This issue is fixed in version 17.0.3.

What this vulnerability is in plain English and why it matters. Sangoma FreePBX Endpoint Manager contains an OS command injection flaw that lets an authenticated user run operating-system commands on the server. An attacker who already holds valid credentials can abuse the testconnection feature to gain remote access to the system running as the asterisk user. This matters because FreePBX systems often manage voice infrastructure and sit on internal networks; successful exploitation gives an attacker a foothold that can be used to move laterally or access call data and configuration.

How it works

The weakness is categorized as CWE-78, improper neutralization of special elements used in an OS command. The vulnerability exists in the check_ssh_connect() function called by the testconnection endpoint. An authenticated user supplies input that is concatenated into a system command without sufficient sanitization, allowing the attacker to append additional commands that execute with the privileges of the asterisk account.

Am I affected? How to find it in your systems

Inventory all deployments of Sangoma FreePBX and confirm whether the Endpoint Manager module is installed and enabled. Review administrative accounts and any external exposure of the web interface, because the flaw requires valid credentials. Examine logs for unusual activity around the testconnection endpoint or repeated SSH-related test calls; specific indicators of exploitation must be confirmed against the vendor advisory.

How to remediate

Apply the vendor-supplied update that addresses the command-injection issue in Endpoint Manager. After patching, verify that the testconnection functionality no longer accepts unsanitized input and that administrative access remains restricted to authorized users only.

If you can't patch immediately

Until the update can be applied, reduce exposure by limiting network reachability of the management interface and by monitoring for anomalous command execution or new outbound connections from the asterisk user. Apply any virtual-patching rules or web-application firewall signatures supplied by the vendor; if no mitigations are available, discontinue use of the affected module as directed by CISA guidance.

If your data may have been exposed

Actively exploited command-injection vulnerabilities can lead to unauthorized access and data exposure. Review authentication records and system logs for signs of misuse, and confirm the scope of any potential access against the vendor advisory. You can run a free exposure scan of your email addresses to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSangoma · FreePBX
WeaknessCWE-78
CVSS base score8.6 (High)
CVSS vectorCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
PublishedNov 7, 2025
Added to CISA KEVFeb 3, 2026
Federal patch deadlineFeb 24, 2026
Known ransomware useNot documented
Check if your data is exposed →

References

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities