CVE-2025-54995: Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54995?
CVE-2025-54995 is considered a medium severity vulnerability due to potential resource exhaustion and disclosure risks.
How do I fix CVE-2025-54995?
To fix CVE-2025-54995, upgrade Asterisk to version 18.26.4 or 18.9-cert17 or higher.
What are the potential impacts of CVE-2025-54995?
The potential impacts of CVE-2025-54995 include leaks of RTP UDP ports and internal resource exhaustion.
Which versions of Asterisk are affected by CVE-2025-54995?
Asterisk versions prior to 18.26.4 and 18.9-cert17 are affected by CVE-2025-54995.
Is there a patch available for CVE-2025-54995?
Yes, CVE-2025-54995 has a patch available in the updated versions of Asterisk since 18.26.4 and 18.9-cert17.