Threat reportVulnerabilityTL-2026-0058
Sangoma FreePBX Authentication Bypass & Command Injection - CISA KEV
Sangoma FreePBX Authentication Bypass & Command Injection (TL-2026-0058) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-02-03. It is attributed to INJ3CTOR3 (Palestine) with medium confidence, affects Sangoma FreePBX, references 2 CVEs (CVE-2019-19006, CVE-2025-64328), maps to 41 MITRE ATT&CK techniques (T1005, T1016, T1021), and is covered by 22 detection rules and 93 indicators of compromise.
- CVSS
- 9.8/10Critical
- CVEs
- 2Referenced vulnerabilities
- Techniques
- 41MITRE ATT&CK
- Actors
- 1INJ3CTOR3
- Detection rules
- 22SPL · KQL · Sigma
- IOCs
- 93Indicators of compromise
Key facts for TL-2026-0058
- Threat ID
- TL-2026-0058
- Severity
- CRITICAL
- CVSS
- 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution
- INJ3CTOR3
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Palestine
- Motivation
- FINANCIAL
- Target sectors
- Telecommunications, Technology, Healthcare, Financial Services, Government, Education, Small/Medium Business
- Target regions
- Global, Middle East, South Asia, Latin America
- Detection rules
- 22
- Indicators of compromise
- 93
Malware and tooling in Sangoma FreePBX Authentication Bypass & Command Injection
Malware and tooling: EncystPHP webshell in FreePBX web root, HTTP POST with cmd=/exec=/shell= parameters to PHP files in FreePBX admin directories, New .php file created in FreePBX web root via php file_put_contents(), PHP/EncystPHP.A!tr, BASH/EncystPHP.A!tr, EncystPHP 'Ask Master' web shell interface, SIPVicious (svmap module) for SIP server scanning and discovery
How Sangoma FreePBX Authentication Bypass & Command Injection works
Sangoma FreePBX Authentication Bypass (CVE-2019-19006) + Endpoint Manager Command Injection (CVE-2025-64328) — INJ3CTOR3 VoIP Exploitation Campaign, EncystPHP Web Shell, International Premium Rate Number (IPRN) Toll Fraud, CISA KEV Dual Entry, Asterisk PBX Monetization
Dual-CVE critical vulnerability chain in Sangoma FreePBX/Asterisk PBX systems, both in CISA's Known Exploited Vulnerabilities catalog. CVE-2019-19006 (CVSS 9.8) is an authentication bypass in FreePBX Framework where sending the password parameter as an array element (password[0]) causes the authentication function to fail before unsetting the session, granting admin access without valid credentials. CVE-2025-64328 (CWE-78, CVSS 8.6) is a post-authentication command injection in FreePBX Endpoint Manager v17.0.2.36-17.0.3 via the testconnection → check_ssh_connect() function, allowing authenticated users to execute arbitrary shell commands as the asterisk user. These vulnerabilities are chained by the INJ3CTOR3 threat actor group (active since 2020, Gaza/West Bank/Egypt nexus): CVE-2019-19006 provides unauthenticated admin access, then CVE-2025-64328 or the asterisk-cli module provides command execution for deploying web shells. The latest campaign (Dec 2025-present) deploys 'EncystPHP' — a sophisticated PHP web shell discovered by FortiGuard Labs that masquerades as legitimate FreePBX files (ajax.php), features multi-layer persistence via cron jobs + SSH key injection + multiple web shell copies, deletes competing web shells, creates root-level backdoor users, and exposes an 'Ask Master' command panel for arbitrary execution and PBX call control. The business model: compromise PBX → make calls to International Premium Rate Numbers (IPRN) → generate revenue per minute. Asterisk is the world's most popular VoIP PBX system used by Fortune 500 companies. CISA deadlines: CVE-2019-19006 due Feb 24, 2026; CVE-2025-64328 due Feb 24, 2026.
MITRE ATT&CK techniques used in TL-2026-0058
collection
T1005 Data from Local System; T1213 Data from Information Repositories
discovery
T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery
lateral-movement
T1021 Remote Services; T1210 Exploitation of Remote Services
defense-evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts
persistence
T1037 Boot or Logon Initialization Scripts; T1098 Account Manipulation; T1136 Create Account; T1505 Server Software Component
credential-access
T1040 Network Sniffing; T1110 Brute Force; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
execution
T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution
privilege-escalation
T1068 Exploitation for Privilege Escalation
command-and-control
T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer
initial-access
T1190 Exploit Public-Facing Application
impact
T1496 Resource Hijacking; T1657 Financial Theft
exfiltration
T1567 Exfiltration Over Web Service
stealth
resource-development
T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities
reconnaissance
defense-impairment
Affected products and versions in Sangoma FreePBX Authentication Bypass & Command Injection
- Sangoma — FreePBX
Vulnerable versions: All versions prior to patch
Fixed in: Patched versions - Sangoma — FreePBX Endpoint Manager
Vulnerable versions: All versions prior to patch
Fixed in: Patched versions
Remediation for Sangoma FreePBX Authentication Bypass & Command Injection
Patches
- [object Object]
Immediate actions
- Update FreePBX to the latest patched version immediately
- Apply vendor security fixes per CISA guidance
- If patches unavailable, consider disabling the Endpoint Manager module
- Restrict admin interface access to trusted IPs only
Workarounds
- Disable Endpoint Manager module
- Restrict admin interface to trusted IPs only
Longer-term hardening
- Monitor for web shell artifacts on FreePBX servers
- Implement web application firewall (WAF) rules
- Regular security audits of VoIP infrastructure
CVEs associated with Sangoma FreePBX Authentication Bypass & Command Injection
Weaknesses (CWE) in Sangoma FreePBX Authentication Bypass & Command Injection
Timeline of Sangoma FreePBX Authentication Bypass & Command Injection
- FreePBX publishes SEC-2019-001 — Remote Admin Authentication Bypass (CVE-2019-19006). Password parameter sent as array element bypasses authentication, granting admin access. CVSS 9.8. Source: https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772
- CVE-2019-19006 published — Sangoma FreePBX remote admin authentication bypass via array parameter injection in password field. CVSS 9.8 Critical. Source: https://nvd.nist.gov/vuln/detail/CVE-2019-19006
- Check Point Research observes INJ3CTOR3 group systematically exploiting CVE-2019-19006 worldwide. Attacks use SIPVicious for scanning, exploit auth bypass for admin access, upload PHP web shells, and abuse PBX for unauthorized outbound calls and telephony fraud. Source: https://research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/
- Check Point Research publishes 'INJ3CTOR3 Operation' — systematic exploitation of SIP servers worldwide using CVE-2019-19006. Attack flow: SIPVicious scan → auth bypass → web shell upload → IPRN toll fraud. Threat actor linked to Gaza/West Bank/Egypt via Facebook groups. Source: https://research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/
- Check Point Research publishes comprehensive analysis of INJ3CTOR3 operation, identifying threat actors primarily from Gaza, West Bank, and Egypt. Group coordinates via Facebook groups and sells access to compromised VoIP systems. Source: Check Point Research
- CISA adds CVE-2019-19006 to Known Exploited Vulnerabilities catalog. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19006
- INJ3CTOR3 shifts focus to Elastix systems via CVE-2021-45461. Same operational pattern: exploit VoIP system → deploy web shell → monetize via IPRN fraud. Source: FortiGuard Labs EncystPHP report.
- INJ3CTOR3 shifts focus to Elastix systems via CVE-2021-45461, demonstrating ongoing evolution and adaptation to new VoIP targets. Source: Fortinet EncystPHP report
- Vulnerability introduced in FreePBX Endpoint Manager around March 2025. Command injection in filestore module testconnection → check_ssh_connect() function. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
- CVE-2025-64328 vulnerability introduced in FreePBX Endpoint Manager around March 2025 in the filestore module's check_ssh_connect() function. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
- GHSA-vm9p-46mv-5xvw published — Authenticated Command Injection in FreePBX Administration GUI. CVE-2025-64328 assigned. Fixed in Endpoint Manager 17.0.3. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
- GitHub Security Advisory GHSA-vm9p-46mv-5xvw published for CVE-2025-64328 — authenticated command injection in FreePBX Administration GUI via filestore SSH testconnection. CVSS 8.6. Fixed in Endpoint Manager 17.0.3. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
- FortiGuard Labs observes first EncystPHP incidents — exploitation of CVE-2025-64328 to deploy sophisticated PHP web shell. Attack originates from Brazil, targets Indian IT company. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
- FortiGuard Labs observes EncystPHP web shell deployment incidents exploiting CVE-2025-64328. Attacks originate from Brazil (45.234.176.202 / crm.razatelefonia.pro) targeting an Indian technology company managing cloud and communication infrastructure. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
- Fortinet publishes comprehensive EncystPHP analysis documenting: 4-stage persistence, 12+ web shell deployment paths, root user creation, SSH key injection, anti-forensics capabilities, and link to INJ3CTOR3 group. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
- CISA adds BOTH CVE-2019-19006 and CVE-2025-64328 to KEV catalog on the same day. Federal remediation deadline: February 24, 2026. Confirms active exploitation of both vulnerabilities. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- CISA adds CVE-2025-64328 to Known Exploited Vulnerabilities catalog. Remediation deadline: 2026-02-24. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64328
- FortiGuard Labs publishes comprehensive EncystPHP analysis — web shell features, persistence mechanisms, IOCs. Links campaign to INJ3CTOR3 group. IPS signature released: 59448. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
- As of 2026-05-29, this is still active: though CVE-2025-64328 was patched in FreePBX 17.0.3 and both CVEs sit in CISA KEV (deadline 2026-02-24), INJ3CTOR3 is still operating and self-healing EncystPHP/JOMANGY web shells persist. Cyble/Cryptika report 700+ of the 900+ compromised systems still infected in May 2026, with toll-fraud ongoing.
Sources cited for Sangoma FreePBX Authentication Bypass & Command Injection
- Fortinet: Unveiling the Weaponized Web Shell EncystPHP
- NVD: CVE-2025-64328
- NVD: CVE-2019-19006
- GitHub Advisory: GHSA-vm9p-46mv-5xvw
- CISA KEV: CVE-2025-64328
- CISA KEV: CVE-2019-19006
- Check Point Research: INJ3CTOR3 Operation
- FreePBX Vulnerable Source Code
- FreePBX Security Blog
- FreePBX Community Advisory: SEC-2019-001
- CISA KEV Catalog — CVE-2019-19006 + CVE-2025-64328
Detection coverage for TL-2026-0058
As of 2026-02-03, Threadlinqs Intelligence publishes 22 detection rule(s) for TL-2026-0058 across Splunk SPL, Microsoft KQL and Sigma, covering 93 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.