Threat reportVulnerabilityTL-2026-0058

Sangoma FreePBX Authentication Bypass & Command Injection - CISA KEV

criticalACTIVE

Sangoma FreePBX Authentication Bypass & Command Injection (TL-2026-0058) is a critical-severity software vulnerability scored CVSS 9.8, first published 2026-02-03. It is attributed to INJ3CTOR3 (Palestine) with medium confidence, affects Sangoma FreePBX, references 2 CVEs (CVE-2019-19006, CVE-2025-64328), maps to 41 MITRE ATT&CK techniques (T1005, T1016, T1021), and is covered by 22 detection rules and 93 indicators of compromise.

CVSS
9.8/10Critical
CVEs
2Referenced vulnerabilities
Techniques
41MITRE ATT&CK
Actors
1INJ3CTOR3
Detection rules
22SPL · KQL · Sigma
IOCs
93Indicators of compromise

Key facts for TL-2026-0058

Threat ID
TL-2026-0058
Severity
CRITICAL
CVSS
9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution
INJ3CTOR3
Attribution confidence
MEDIUM
Nation-state nexus
Palestine
Motivation
FINANCIAL
Target sectors
Telecommunications, Technology, Healthcare, Financial Services, Government, Education, Small/Medium Business
Target regions
Global, Middle East, South Asia, Latin America
Detection rules
22
Indicators of compromise
93

Malware and tooling in Sangoma FreePBX Authentication Bypass & Command Injection

Malware and tooling: EncystPHP webshell in FreePBX web root, HTTP POST with cmd=/exec=/shell= parameters to PHP files in FreePBX admin directories, New .php file created in FreePBX web root via php file_put_contents(), PHP/EncystPHP.A!tr, BASH/EncystPHP.A!tr, EncystPHP 'Ask Master' web shell interface, SIPVicious (svmap module) for SIP server scanning and discovery

How Sangoma FreePBX Authentication Bypass & Command Injection works

Sangoma FreePBX Authentication Bypass (CVE-2019-19006) + Endpoint Manager Command Injection (CVE-2025-64328) — INJ3CTOR3 VoIP Exploitation Campaign, EncystPHP Web Shell, International Premium Rate Number (IPRN) Toll Fraud, CISA KEV Dual Entry, Asterisk PBX Monetization

Dual-CVE critical vulnerability chain in Sangoma FreePBX/Asterisk PBX systems, both in CISA's Known Exploited Vulnerabilities catalog. CVE-2019-19006 (CVSS 9.8) is an authentication bypass in FreePBX Framework where sending the password parameter as an array element (password[0]) causes the authentication function to fail before unsetting the session, granting admin access without valid credentials. CVE-2025-64328 (CWE-78, CVSS 8.6) is a post-authentication command injection in FreePBX Endpoint Manager v17.0.2.36-17.0.3 via the testconnection → check_ssh_connect() function, allowing authenticated users to execute arbitrary shell commands as the asterisk user. These vulnerabilities are chained by the INJ3CTOR3 threat actor group (active since 2020, Gaza/West Bank/Egypt nexus): CVE-2019-19006 provides unauthenticated admin access, then CVE-2025-64328 or the asterisk-cli module provides command execution for deploying web shells. The latest campaign (Dec 2025-present) deploys 'EncystPHP' — a sophisticated PHP web shell discovered by FortiGuard Labs that masquerades as legitimate FreePBX files (ajax.php), features multi-layer persistence via cron jobs + SSH key injection + multiple web shell copies, deletes competing web shells, creates root-level backdoor users, and exposes an 'Ask Master' command panel for arbitrary execution and PBX call control. The business model: compromise PBX → make calls to International Premium Rate Numbers (IPRN) → generate revenue per minute. Asterisk is the world's most popular VoIP PBX system used by Fortune 500 companies. CISA deadlines: CVE-2019-19006 due Feb 24, 2026; CVE-2025-64328 due Feb 24, 2026.

MITRE ATT&CK techniques used in TL-2026-0058

collection

T1005 Data from Local System; T1213 Data from Information Repositories

discovery

T1016 System Network Configuration Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1087 Account Discovery

lateral-movement

T1021 Remote Services; T1210 Exploitation of Remote Services

defense-evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts; T1140 Deobfuscate/Decode Files or Information; T1564 Hide Artifacts

persistence

T1037 Boot or Logon Initialization Scripts; T1098 Account Manipulation; T1136 Create Account; T1505 Server Software Component

credential-access

T1040 Network Sniffing; T1110 Brute Force; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

execution

T1053 Scheduled Task/Job; T1059 Command and Scripting Interpreter; T1203 Exploitation for Client Execution

privilege-escalation

T1068 Exploitation for Privilege Escalation

command-and-control

T1071 Application Layer Protocol; T1090 Proxy; T1102 Web Service; T1105 Ingress Tool Transfer

initial-access

T1190 Exploit Public-Facing Application

impact

T1496 Resource Hijacking; T1657 Financial Theft

exfiltration

T1567 Exfiltration Over Web Service

stealth

T1574 Hijack Execution Flow

resource-development

T1583 Acquire Infrastructure; T1587 Develop Capabilities; T1588 Obtain Capabilities

reconnaissance

T1595 Active Scanning

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Sangoma FreePBX Authentication Bypass & Command Injection

  • Sangoma — FreePBX
    Vulnerable versions: All versions prior to patch
    Fixed in: Patched versions
  • Sangoma — FreePBX Endpoint Manager
    Vulnerable versions: All versions prior to patch
    Fixed in: Patched versions

Remediation for Sangoma FreePBX Authentication Bypass & Command Injection

Patches

  • [object Object]

Immediate actions

  • Update FreePBX to the latest patched version immediately
  • Apply vendor security fixes per CISA guidance
  • If patches unavailable, consider disabling the Endpoint Manager module
  • Restrict admin interface access to trusted IPs only

Workarounds

  • Disable Endpoint Manager module
  • Restrict admin interface to trusted IPs only

Longer-term hardening

  • Monitor for web shell artifacts on FreePBX servers
  • Implement web application firewall (WAF) rules
  • Regular security audits of VoIP infrastructure

CVEs associated with Sangoma FreePBX Authentication Bypass & Command Injection

CVE-2019-19006, CVE-2025-64328

Weaknesses (CWE) in Sangoma FreePBX Authentication Bypass & Command Injection

CWE-287, CWE-78

Timeline of Sangoma FreePBX Authentication Bypass & Command Injection

  • FreePBX publishes SEC-2019-001 — Remote Admin Authentication Bypass (CVE-2019-19006). Password parameter sent as array element bypasses authentication, granting admin access. CVSS 9.8. Source: https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772
  • CVE-2019-19006 published — Sangoma FreePBX remote admin authentication bypass via array parameter injection in password field. CVSS 9.8 Critical. Source: https://nvd.nist.gov/vuln/detail/CVE-2019-19006
  • Check Point Research observes INJ3CTOR3 group systematically exploiting CVE-2019-19006 worldwide. Attacks use SIPVicious for scanning, exploit auth bypass for admin access, upload PHP web shells, and abuse PBX for unauthorized outbound calls and telephony fraud. Source: https://research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/
  • Check Point Research publishes 'INJ3CTOR3 Operation' — systematic exploitation of SIP servers worldwide using CVE-2019-19006. Attack flow: SIPVicious scan → auth bypass → web shell upload → IPRN toll fraud. Threat actor linked to Gaza/West Bank/Egypt via Facebook groups. Source: https://research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/
  • Check Point Research publishes comprehensive analysis of INJ3CTOR3 operation, identifying threat actors primarily from Gaza, West Bank, and Egypt. Group coordinates via Facebook groups and sells access to compromised VoIP systems. Source: Check Point Research
  • CISA adds CVE-2019-19006 to Known Exploited Vulnerabilities catalog. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19006
  • INJ3CTOR3 shifts focus to Elastix systems via CVE-2021-45461. Same operational pattern: exploit VoIP system → deploy web shell → monetize via IPRN fraud. Source: FortiGuard Labs EncystPHP report.
  • INJ3CTOR3 shifts focus to Elastix systems via CVE-2021-45461, demonstrating ongoing evolution and adaptation to new VoIP targets. Source: Fortinet EncystPHP report
  • Vulnerability introduced in FreePBX Endpoint Manager around March 2025. Command injection in filestore module testconnection → check_ssh_connect() function. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
  • CVE-2025-64328 vulnerability introduced in FreePBX Endpoint Manager around March 2025 in the filestore module's check_ssh_connect() function. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
  • GHSA-vm9p-46mv-5xvw published — Authenticated Command Injection in FreePBX Administration GUI. CVE-2025-64328 assigned. Fixed in Endpoint Manager 17.0.3. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
  • GitHub Security Advisory GHSA-vm9p-46mv-5xvw published for CVE-2025-64328 — authenticated command injection in FreePBX Administration GUI via filestore SSH testconnection. CVSS 8.6. Fixed in Endpoint Manager 17.0.3. Source: https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw
  • FortiGuard Labs observes first EncystPHP incidents — exploitation of CVE-2025-64328 to deploy sophisticated PHP web shell. Attack originates from Brazil, targets Indian IT company. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
  • FortiGuard Labs observes EncystPHP web shell deployment incidents exploiting CVE-2025-64328. Attacks originate from Brazil (45.234.176.202 / crm.razatelefonia.pro) targeting an Indian technology company managing cloud and communication infrastructure. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
  • Fortinet publishes comprehensive EncystPHP analysis documenting: 4-stage persistence, 12+ web shell deployment paths, root user creation, SSH key injection, anti-forensics capabilities, and link to INJ3CTOR3 group. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
  • CISA adds BOTH CVE-2019-19006 and CVE-2025-64328 to KEV catalog on the same day. Federal remediation deadline: February 24, 2026. Confirms active exploitation of both vulnerabilities. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  • CISA adds CVE-2025-64328 to Known Exploited Vulnerabilities catalog. Remediation deadline: 2026-02-24. Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64328
  • FortiGuard Labs publishes comprehensive EncystPHP analysis — web shell features, persistence mechanisms, IOCs. Links campaign to INJ3CTOR3 group. IPS signature released: 59448. Source: https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp
  • As of 2026-05-29, this is still active: though CVE-2025-64328 was patched in FreePBX 17.0.3 and both CVEs sit in CISA KEV (deadline 2026-02-24), INJ3CTOR3 is still operating and self-healing EncystPHP/JOMANGY web shells persist. Cyble/Cryptika report 700+ of the 900+ compromised systems still infected in May 2026, with toll-fraud ongoing.

Sources cited for Sangoma FreePBX Authentication Bypass & Command Injection

Detection coverage for TL-2026-0058

As of 2026-02-03, Threadlinqs Intelligence publishes 22 detection rule(s) for TL-2026-0058 across Splunk SPL, Microsoft KQL and Sigma, covering 93 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

22 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
93 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats