# Sangoma FreePBX Authentication Bypass & Command Injection - CISA KEV

> Sangoma FreePBX Authentication Bypass (CVE-2019-19006) + Endpoint Manager Command Injection (CVE-2025-64328) — INJ3CTOR3 VoIP Exploitation Campaign, EncystPHP Web Shell, International Premium Rate Number (IPRN) Toll Fraud, CISA KEV Dual Entry, Asterisk PBX Monetization

- **Published:** 2026-02-03T19:00:00Z
- **Last reviewed:** 2026-02-03T19:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0058
- **ID:** TL-2026-0058
- **Severity:** CRITICAL (CVSS 9.8)
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Actor:** INJ3CTOR3 (Palestine)
- **Detections:** 22 · **IOCs:** 93 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2019-19006, CVE-2025-64328

## Description

Dual-CVE critical vulnerability chain in Sangoma FreePBX/Asterisk PBX systems, both in CISA's Known Exploited Vulnerabilities catalog. CVE-2019-19006 (CVSS 9.8) is an authentication bypass in FreePBX Framework where sending the password parameter as an array element (password[0]) causes the authentication function to fail before unsetting the session, granting admin access without valid credentials. CVE-2025-64328 (CWE-78, CVSS 8.6) is a post-authentication command injection in FreePBX Endpoint Manager v17.0.2.36-17.0.3 via the testconnection → check_ssh_connect() function, allowing authenticated users to execute arbitrary shell commands as the asterisk user. These vulnerabilities are chained by the INJ3CTOR3 threat actor group (active since 2020, Gaza/West Bank/Egypt nexus): CVE-2019-19006 provides unauthenticated admin access, then CVE-2025-64328 or the asterisk-cli module provides command execution for deploying web shells. The latest campaign (Dec 2025-present) deploys 'EncystPHP' — a sophisticated PHP web shell discovered by FortiGuard Labs that masquerades as legitimate FreePBX files (ajax.php), features multi-layer persistence via cron jobs + SSH key injection + multiple web shell copies, deletes competing web shells, creates root-level backdoor users, and exposes an 'Ask Master' command panel for arbitrary execution and PBX call control. The business model: compromise PBX → make calls to International Premium Rate Numbers (IPRN) → generate revenue per minute. Asterisk is the world's most popular VoIP PBX system used by Fortune 500 companies. CISA deadlines: CVE-2019-19006 due Feb 24, 2026; CVE-2025-64328 due Feb 24, 2026.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1053 Scheduled Task/Job
- T1505 Server Software Component
- T1098 Account Manipulation
- T1136 Create Account
- T1068 Exploitation for Privilege Escalation
- T1070 Indicator Removal
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1555 Credentials from Password Stores
- T1552 Unsecured Credentials
- T1082 System Information Discovery
- T1046 Network Service Discovery
- T1083 File and Directory Discovery
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1105 Ingress Tool Transfer
- T1595 Active Scanning
- T1496 Resource Hijacking
- T1078 Valid Accounts
- T1040 Network Sniffing
- T1657 Financial Theft
- T1213 Data from Information Repositories
- T1210 Exploitation of Remote Services
- T1203 Exploitation for Client Execution
- T1140 Deobfuscate/Decode Files or Information
- T1021 Remote Services
- T1102 Web Service
- T1588 Obtain Capabilities
- T1037 Boot or Logon Initialization Scripts
- T1574 Hijack Execution Flow
- T1685 Disable or Modify Tools
- T1564 Hide Artifacts
- T1110 Brute Force
- T1087 Account Discovery
- T1016 System Network Configuration Discovery
- T1090 Proxy
- T1567 Exfiltration Over Web Service
- T1583 Acquire Infrastructure

## Sources

- [Fortinet: Unveiling the Weaponized Web Shell EncystPHP](https://www.fortinet.com/blog/threat-research/unveiling-the-weaponized-web-shell-encystphp)
- [NVD: CVE-2025-64328](https://nvd.nist.gov/vuln/detail/CVE-2025-64328)
- [NVD: CVE-2019-19006](https://nvd.nist.gov/vuln/detail/CVE-2019-19006)
- [GitHub Advisory: GHSA-vm9p-46mv-5xvw](https://github.com/FreePBX/security-reporting/security/advisories/GHSA-vm9p-46mv-5xvw)
- [CISA KEV: CVE-2025-64328](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-64328)
- [CISA KEV: CVE-2019-19006](https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19006)
- [Check Point Research: INJ3CTOR3 Operation](https://research.checkpoint.com/2020/inj3ctor3-operation-leveraging-asterisk-servers-for-monetization/)
- [FreePBX Vulnerable Source Code](https://github.com/FreePBX/filestore/blob/f0e3983059271efd80b483ec823310ef19a59013/drivers/SSH/testconnection.php#L2)
- [FreePBX Security Blog](https://www.freepbx.org/watch-what-we-do-with-security-fixes-%f0%9f%91%80)
- [FreePBX Community Advisory: SEC-2019-001](https://community.freepbx.org/t/freepbx-security-vulnerability-sec-2019-001/62772)
- [CISA KEV Catalog — CVE-2019-19006 + CVE-2025-64328](https://www.cisa.gov/known-exploited-vulnerabilities-catalog)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0058
