Detects FreePBX phone systems whose database can be read and rewritten by anyone on the internet, with no login. FreePBX 15, 16 and 17 running the Endpoint Manager module below 15.0.66 / 16.0.89 / 17.0.3 accept a namespaced class name in the module parameter of /admin/ajax.php. The framework autoloader turns that into a file path and runs the module's provisioning handler before the session check happens, and that handler pastes the brand parameter straight into a SQL query. We prove it without writing anything: we ask the target's own database to multiply two random numbers and read the product back out of its error message. The same request accepts extra statements, which is how attackers added themselves as PBX administrators and scheduled commands that run as root. CISA lists this as actively exploited since August 2025. Update Endpoint Manager to 15.0.66, 16.0.89 or 17.0.3 or later, update the framework, and keep /admin off the public internet.
Is your app exploitable through CVE-2025-57819?
Scan your domain free