<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Sangoma</title><description>Actively exploited vulnerabilities affecting Sangoma products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/sangoma.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2019-19006 —  Sangoma FreePBX Improper Authentication Vulnerability</title><link>https://wildfortech.com/security#CVE-2019-19006</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2019-19006</guid><description>FreePBX is a widely used web-based open-source GUI for managing Asterisk-based phone systems. This vulnerability allows attackers to bypass password authentication entirely, potentially gaining unauthorized access to the FreePBX admin interface. From there, an attacker could manipulate phone system configurations, intercept calls, redirect traffic, or pivot further into the network. Any internet-exposed FreePBX instance is at significant risk, making this a high-priority issue for organizations running VoIP infrastructure.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><category>Sangoma</category><category>FreePBX</category></item><item><title>CVE-2025-64328 — Sangoma FreePBX OS Command Injection Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-64328</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-64328</guid><description>Sangoma FreePBX Endpoint Manager contains a command injection flaw that authenticated users can exploit through the check_ssh_connect() function. Because FreePBX is widely used in business VoIP environments, a malicious insider or an attacker who has obtained valid credentials could execute arbitrary OS commands, potentially gaining remote shell access as the &apos;asterisk&apos; system user — opening the door to full system compromise of the phone infrastructure.</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><category>Sangoma</category><category>FreePBX </category></item><item><title>CVE-2025-57819 — Sangoma FreePBX Authentication Bypass Vulnerability</title><link>https://wildfortech.com/security#CVE-2025-57819</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2025-57819</guid><description>This vulnerability in Sangoma FreePBX allows unauthenticated attackers to bypass the login process entirely due to improper sanitization of user-supplied data. Once inside, an attacker can manipulate the underlying database and execute arbitrary code remotely. For organizations running FreePBX — a widely used open-source PBX management platform — this means full system compromise is possible without any valid credentials, making it a critical risk to phone infrastructure and potentially broader network environments.</description><pubDate>Fri, 29 Aug 2025 00:00:00 GMT</pubDate><category>Sangoma</category><category>FreePBX</category></item></channel></rss>