CVE-2025-1131: Asterisk Unsafe Shell Sourcing in safe_asterisk Leads to Local Privilege Escalation

Published Sep 23, 2025
·
Updated

A local privilege escalation vulnerability exists in the safeasterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions.

Non-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.

Affected Software

31 affected components
Asterisk Asterisk
Sangoma Asterisk<18.26.3
Sangoma Asterisk>=20.0.0<20.15.1
Sangoma Asterisk>=21.0.0<21.10.1
Sangoma Asterisk>=22.0.0<22.5.1
Sangoma Certified Asterisk=18.9-cert1
Sangoma Certified Asterisk=18.9-cert1-rc1
Sangoma Certified Asterisk=18.9-cert10
Sangoma Certified Asterisk=18.9-cert11
Sangoma Certified Asterisk=18.9-cert12
Sangoma Certified Asterisk=18.9-cert13
Sangoma Certified Asterisk=18.9-cert14
Sangoma Certified Asterisk=18.9-cert15
Sangoma Certified Asterisk=18.9-cert2
Sangoma Certified Asterisk=18.9-cert3
Sangoma Certified Asterisk=18.9-cert4
Sangoma Certified Asterisk=18.9-cert5
Sangoma Certified Asterisk=18.9-cert6
Sangoma Certified Asterisk=18.9-cert7
Sangoma Certified Asterisk=18.9-cert8
Sangoma Certified Asterisk=18.9-cert8-rc1
Sangoma Certified Asterisk=18.9-cert8-rc2
Sangoma Certified Asterisk=18.9-cert9
Sangoma Certified Asterisk=20.7-cert1
Sangoma Certified Asterisk=20.7-cert1-rc1
Sangoma Certified Asterisk=20.7-cert1-rc2
Sangoma Certified Asterisk=20.7-cert2
Sangoma Certified Asterisk=20.7-cert3
Sangoma Certified Asterisk=20.7-cert4
Sangoma Certified Asterisk=20.7-cert5
Sangoma Certified Asterisk=20.7-cert6

Event History

Sep 23, 2025
CVE Published
via MITRE·04:31 AM
Data Sourced
via MITRE·04:31 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-1131?

CVE-2025-1131 is categorized as a local privilege escalation vulnerability.

2

How does CVE-2025-1131 affect Asterisk installations?

CVE-2025-1131 affects Asterisk installations when the safe_asterisk script is used to start Asterisk as it allows unauthorized scripts to run with root privileges.

3

How can I mitigate CVE-2025-1131?

To mitigate CVE-2025-1131, ensure that the /etc/asterisk/startup.d/ directory is secured and review the scripts located there for any unauthorized changes.

4

Is there a patch available for CVE-2025-1131?

As of now, please check Asterisk's official channels for an update or patch addressing CVE-2025-1131.

5

Who is affected by CVE-2025-1131?

Any user of Asterisk running the safe_asterisk script within a SysV init or FreePBX environment is affected by CVE-2025-1131.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203