CVE-2025-67722: Authenticated amportal search for ‘freepbx_engine’ in non root writeable directories leads to potential privilege escalation

Published Dec 16, 2025
·
Updated

FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script amportal. In the deprecated amportal utility, the lookup for the freepbxengine file occurs in /etc/asterisk/ directories. Typically, these are configured by FreePBX as writable by the asterisk user and any members of the asterisk group. This means that a member of the asterisk group can add their own freepbxengine file in /etc/asterisk/ and upon amportal executing, it would exec that file with root permissions (even though the file was created and placed by a non-root user). Version 16.0.45 and 17.0.24 contain a fix for the issue. Other mitigation strategies are also available. Confirm only trusted local OS system users are members of the asterisk group. Look for suspicious files in the /etc/asterisk/ directory (via Admin -> Config Edit in the GUI, or via CLI). Double-check that livedangerously = no is set (or unconfigured, as the default is no) in /etc/asterisk/asterisk.conf file. Eliminate any unsafe custom use of Asterisk dial plan applications and functions that potentially can manipulate the file system, e.g., System(), FILE(), etc.

Affected Software

3 affected components
FreePBX FreePBX<16.0.45, <17.0.24
Sangoma FreePBX >=16.0<16.0.45
Sangoma FreePBX >=17.0<17.0.24

Event History

Dec 16, 2025
CVE Published
via MITRE·12:14 AM
Data Sourced
via MITRE·12:14 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-67722?

CVE-2025-67722 is classified as a high severity vulnerability due to its potential for local privilege escalation.

2

How do I fix CVE-2025-67722?

To fix CVE-2025-67722, upgrade to FreePBX version 16.0.45 or later for 16.x and to 17.0.24 or later for 17.x.

3

What is the impact of CVE-2025-67722?

The impact of CVE-2025-67722 allows authenticated users to escalate their privileges locally within the FreePBX environment.

4

Which versions of FreePBX are affected by CVE-2025-67722?

FreePBX versions prior to 16.0.45 and 17.0.24 are affected by CVE-2025-67722.

5

Is CVE-2025-67722 a remote vulnerability?

No, CVE-2025-67722 is not a remote vulnerability; it requires authenticated local access to exploit.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203