Skip to content
Noroxi

Sangoma records

85 published records for vendor sangoma.

All records

85 records
  • FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE

    CriticalCVSS 10.0KEVWeaponizedEPSS 85%

    sangoma · freepbxAug 28, 2025

  • FreePBX Administration GUI is Vulnerable to Authenticated Command Injection

    HighCVSS 8.6KEVWeaponizedEPSS 85%

    sangoma · filestoreNov 7, 2025

  • Sangoma FreePBX 115.0.16.26 and below, 14.0.13.11 and below, 13.0.197.13 and below have Incorrect Access Control.

    CriticalCVSS 9.8KEVWeaponizedEPSS 56%

    sangoma · freepbxNov 21, 2019

  • CVE-2026-9586
    73This week

    Unauthenticated SQL Injection Leading to Remote Code Execution in Switchvox SMB

    CriticalCVSS 9.3KEVWeaponizedEPSS 19%

    sangoma · switchvoxJul 17, 2026

  • htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 bef

    CriticalCVSS 10.0Proof of conceptEPSS 43%

    freepbx · freepbxOct 7, 2014

  • The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attackers to execute arbitr

    HighCVSS 7.5WeaponizedEPSS 70%

    sangoma · freepbxSep 6, 2012

  • admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12 before 12.0.1alpha22

    HighCVSS 7.5WeaponizedEPSS 53%

    freepbx · freepbxFeb 18, 2014

  • FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to exec

    CriticalCVSS 9.8No exploitEPSS 22%

    sangoma · restappsDec 22, 2021

  • Asterisk Path Traversal vulnerability

    HighCVSS 7.5No exploitEPSS 45%

    digium · asteriskDec 14, 2023

  • Potential integer underflow upon receiving STUN message in PJSIP

    CriticalCVSS 9.8No exploitEPSS 5%

    teluu · pjsipDec 22, 2021

  • Use after free in PJSIP

    CriticalCVSS 9.8No exploitEPSS 4%

    teluu · pjsipFeb 22, 2022

  • The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to an authentication bypass via an argument injection

    CriticalCVSS 9.8No exploitEPSS 4%

    sangoma · session border controller firmwareOct 22, 2019

  • The Sangoma Session Border Controller (SBC) 2.3.23-119 GA web interface is vulnerable to Argument Injection via special characters in the us

    CriticalCVSS 9.8No exploitEPSS 3%

    sangoma · session border controller firmwareOct 22, 2019

  • The restapps (aka Rest Phone apps) module for Sangoma FreePBX and PBXact 13, 14, and 15 through 15.0.19.2 allows remote code execution via a

    CriticalCVSS 9.8No exploitEPSS 2%

    sangoma · restappsMay 31, 2021

  • Sangoma NetBorder / Vega Session Controller before 2.3.12-80-GA allows remote attackers to execute arbitrary commands via the web interface.

    CriticalCVSS 9.8No exploitEPSS 2%

    sangoma · netborder\/vega session firmwareDec 7, 2017

  • Multiple race conditions in WANPIPE before 3.3.6 have unknown impact and attack vectors related to "bri restart logic."

    CriticalCVSS 10.0No exploitEPSS 1%

    sangoma · wanpipeApr 3, 2009

  • A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remote code execution.

    CriticalCVSS 9.8No exploitEPSS 1%

    sangoma · img2020 firmwareJun 3, 2025

  • Insecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function.

    CriticalCVSS 9.8No exploitEPSS 1%

    sangoma · asteriskFeb 5, 2025

  • FreePBX cdr Cdr.class.php ajaxHandler sql injection

    CriticalCVSS 9.8No exploitEPSS 1%

    sangoma · freepbxDec 25, 2022

  • FreePBX Endpoint Manager Allows Unauthenticated Logins to Administrator Control Panel via Forged Basic Auth Header

    CriticalCVSS 9.3WeaponizedEPSS 3%

    sangoma · freepbxDec 9, 2025

  • Out-of-bounds read in multipart parsing in PJSIP

    CriticalCVSS 9.1No exploitEPSS 4%

    teluu · pjsipJan 26, 2022

  • CVE-2012-2186
    37Monitor

    Incomplete blacklist vulnerability in main/manager.c in Asterisk Open Source 1.8.x before 1.8.15.1 and 10.x before 10.7.1, Certified Asteris

    CriticalCVSS 9.0No exploitEPSS 4%

    asterisk · open sourceAug 31, 2012

  • FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Interface

    CriticalCVSS 9.3Proof of conceptEPSS 0%

    sangoma · freepbxMay 29, 2026

  • Authenticated SQL Injection in FreePBX tts (Text To Speech) module

    HighCVSS 8.6No exploitEPSS 6%

    sangoma · freepbxDec 15, 2025

  • FreePBX 16 Authenticated Remote Code Execution via API Module

    HighCVSS 8.7No exploitEPSS 4%

    sangoma · freepbxDec 11, 2025