CVE-2025-1131: Sangoma Asterisk
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions. Non-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.
Affected products
- Sangoma Asterisk: before 18.26.3 (fixed in 18.26.3); from 20.0.0, before 20.15.1 (fixed in 20.15.1); from 21.0.0, before 21.10.1 (fixed in 21.10.1); from 22.0.0, before 22.5.1 (fixed in 22.5.1)
- Sangoma Certified Asterisk: version 18.9 only; version 20.7 only
Published 2025-09-23. Last modified 2026-06-17.