CVE-2025-54995: Sangoma Asterisk

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.

Affected products

  • Sangoma Asterisk: before 18.26.4 (fixed in 18.26.4)
  • Sangoma Certified Asterisk: before 18.9 (fixed in 18.9); version 18.9 only

Published 2025-08-28. Last modified 2026-06-17.