SQL injection in FreePBX - CVE-2025-57819
Published: August 29, 2025 / Updated: June 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient sanitization of user-supplied data within the endpoint module. A remote attacker can send a specially crafted request to the affected application and execute arbitrary SQL commands, leading to system compromise.
Note, the vulnerability is being actively exploited in the wild since August 21, 2025.
Affected software
How to mitigate CVE-2025-57819
Links to Public Exploits and PoC-codes
- Exploit #12774 - CVE-2025-57819-poc (June 23, 2026)
- Exploit #12050 - watchTowr-vs-FreePBX-CVE-2025-57819 (October 31, 2025)
- Exploit #11986 - CVE-2025-57819 (September 24, 2025)
- Exploit #11978 - FreePBX ajax.php unuthenticated SQLi to RCE (September 23, 2025)
- Exploit #11974 - CVE-2025-57819_FreePBX (This repository contains a Proof of Concept (PoC) exploit for CVE-2025-57819, a critical remote code execution vulnerability affecting FreePBX versions 15.x, 16.x, and 17.x.) (September 19, 2025)
- Exploit #11930 - CVE-2025-57819 (September 5, 2025)