CVE-2025-47780: Sangoma Asterisk
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring `cli_permissions.conf` (e.g. with the config line `deny=!*`) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the `cli_permissions.conf` file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
Affected products
- Sangoma Asterisk: before 18.26.2 (fixed in 18.26.2); from 20.0.0, before 20.14.1 (fixed in 20.14.1); from 21.0.0, before 21.9.1 (fixed in 21.9.1); from 22.0.0, before 22.4.1 (fixed in 22.4.1)
- Sangoma Certified Asterisk: before 18.9 (fixed in 18.9); version 18.9 only; version 20.7 only
Published 2025-05-22. Last modified 2026-06-17.