« Back to list

Sangoma

Sangoma Filestore: vulnerabilities and CVEs

Sangoma Filestore has 2 published vulnerabilities, 2 of them in the last 12 months. 1 are rated critical and 1 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical1
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-64328High (8.6)85%⚠ Active exploitationNov 7, 2025
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-39920Critical (9.3)1.1%—Apr 24, 2026
BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated remote attackers to…
CVE-2025-64328High (8.6)85%⚠ Active exploitationNov 7, 2025
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter1
  2. T1190 Exploit Public-Facing Application1
  3. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Sangoma