Junglewise Threat Intelligence

CVE-2025-64328: Sangoma FreePBX command injection in filestore module

CVE-2025-64328 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2025-11-07

Technologies: Sangoma FreePBX. Vendors: Sangoma.

Executive brief

Sangoma FreePBX is a popular open-source communication platform used to manage business phone systems. A security flaw in its endpoint management module allows an authorized administrator to run unauthorized commands on the underlying server. If exploited, an attacker could gain full control over the telephony system, potentially leading to eavesdropping, service disruption, or further access into the corporate network.

Technical details

An OS command injection vulnerability exists in the filestore module of FreePBX 17. The flaw is located within the check_ssh_connect() function of the testconnection.php driver, where user-supplied input is insufficiently sanitized before being passed to system execution functions like exec(). An attacker with administrative privileges to the FreePBX GUI can exploit this via the network to execute arbitrary shell commands as the 'asterisk' user. This vulnerability has been observed being exploited in the wild to deploy the 'EncystPHP' web shell. The issue is resolved in filestore module version 17.0.3.

Affected products

  • Sangoma FreePBX Endpoint Manager (filestore module) 17.0.2.36 up to (but excluding) 17.0.3

Timeline

  • 2025-11-07: disclosed
  • 2025-11-07: advisory
  • 2025-12-01: exploited: Exploitation observed in the wild by Fortinet researchers.
  • 2026-01-28: other: FortiGuard Labs publishes research on EncystPHP web shell using this exploit.
  • 2026-02-03: kev added

References

Related threats