
Detection for CVE-2025-57819
Overview of this vulnerability quoted from @jfinstrom here
- Around 2025-08-21 multiple FreePBX systems began showing errors and later confirmed compromises.
- Vendor (Sangoma/FreePBX Security Team) published an advisory on 2025-08-26 urging administrators to restrict public access to the Administrator Control Panel and offering EDGE module fixes.
- The vulnerability is associated with the commercial Endpoint Manager (Endpoint) and appears to be an unauthenticated privilege escalation/RCE that can be exploited when the Administrator UI is exposed to hostile networks.
- The EDGE fix prevents new exploitation but does not clean already-compromised systems.
This template sends a request to the FreePBX admin panel, extracts the version, and flags it as vulnerable if it falls within the affected version ranges of the newly disclosed zero-day (16.0.0.0–16.0.88.19 or 17.0.0.0–17.0.2.31).
nuclei -u https://yourHost.com -t template.yamlUse at your own risk, I will not be responsible for illegal activities you conduct on infrastructure you do not own or have permission to scan.
Feel free to reach out via Signal if you have any questions.