tag
Asterisk
Critical
FreePBX Unauthenticated SQL Injection to RCE (CVE-2025-57819)
CVE-2025-57819·
Sangoma FreePBX administrator web UI (admin/ajax.php, endpoint module)
patched
Medium
PJSIP DNS Compression Pointer Heap Out-of-Bounds Read (CVE-2026-32945)
CVE-2026-32945·
pjproject (PJSIP library) — used by Asterisk, FreeSWITCH, and other SIP applications
patched