Skip to the content.

DIVD-2025-00038 - Found webshells in FreePBX due to RCE vulnerability

Our reference DIVD-2025-00038
Case lead Stan Plasmeijer
Author Max van der Horst
Researcher(s)
CVE(s)
Products
  • FreePBX
Versions
  • All supported FreePBX versions before v16 with publicly exposed admin interfaces
Recommendation Restrict access to the FreePBX administrator interface (via VPN, firewall, or access control lists). Do not expose it directly to the internet.
Patch status Available
Status Open
Last modified 28 Aug 2025 22:50 CEST

Summary

On 27 August 2025, the FreePBX community issued a security advisory warning of increased exploitation attempts against systems exposing their administrator web interface to the internet. This issue has been assigned CVE-2025-57819.

Attackers target the /admin panel of FreePBX to obtain unauthorized access. If successful, exploitation may lead to remote code execution, privilege escalation, or full system compromise. The advisory highlights that the root problem is the unsafe exposure of the administrator interface, rather than a single patchable flaw.

What you can do

To mitigate CVE-2025-57819, administrators should:

What we are doing

DIVD is investigating the compromise of FreePBX administration interfaces and may notify affected parties. Our aim is to reduce the attack surface and support system owners in remediating the compromise.

Timeline

Date Description
27 Aug 2025 FreePBX community reports surge in exploit attempts and webshells against admin interfaces
28 Aug 2025 CVE-2025-57819 assigned for FreePBX administrator interface exposure
28 Aug 2025 DIVD scans for webshelled instances
gantt title DIVD-2025-00038 - Found webshells in FreePBX due to RCE vulnerability dateFormat YYYY-MM-DD axisFormat %e %b %Y section Case DIVD-2025-00038 - Found webshells in FreePBX due to RCE vulnerability (still open) :2025-08-27, 2025-09-04 section Events FreePBX community reports surge in exploit attempts and webshells against admin interfaces : milestone, 2025-08-27, 0d CVE-2025-57819 assigned for FreePBX administrator interface exposure : milestone, 2025-08-28, 0d DIVD scans for webshelled instances : milestone, 2025-08-28, 0d

More information