A critical SQL injection in FreePBX is emerging as a significant threat to VoIP infrastructures worldwide, allowing attackers to manipulate database contents and achieve arbitrary code execution.
See also: Malicious users take over MS-SQL Server and deploy XiebroC2

FreePBX, a widely used PBX system based on the open-source Asterisk VoIP, provides organizations with the ability to manage their telecommunications infrastructure via web-based management. The vulnerability, which has been designated as CVE-2025-57819, allows malicious users to inject SQL commands via vulnerable web application parameters, specifically targeting the system's database management functions.
Malicious users are actively exploiting this vulnerability to compromise FreePBX installations through sophisticated database manipulation techniques. The attack method leverages the ajax.php endpoint , where inadequate input sanitization allows SQL injection via the “brand” parameter. Attackers craft malicious GET requests containing SQL payloads, which insert unauthorized records into the cron_jobs, essentially creating persistent access mechanisms to the compromised system.
See also: Security in Web Applications: SQL Injection, XSS, CSRF and WAF

Internet Storm Center analysts have identified this vulnerability in active exploitation campaigns, noting that attackers are using the vulnerability to achieve a complete compromise of the system. The exploitation attempts demonstrate advanced techniques that go beyond simple database manipulation, incorporating persistent and stealth access elements to maintain unauthorized access while avoiding detection.
The exploitation methodology involves injecting carefully crafted SQL statements into the FreePBX database via the vulnerable brand parameter in ajax.php requests. The malicious payload inserts a new entry into the cron_jobs table, which FreePBX uses to manage scheduled tasks.
See also: How to protect yourself from malicious SQL Commands

The command, encoded in base64, when decoded reveals a PHP script containing: This technique turns database manipulation into direct code execution, exploiting FreePBX's cron job management system, creating web-accessible PHP files that execute system commands while implementing self-deleting mechanisms to evade forensic analysis.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
