Vulnerability Description
A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions. Non-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sangoma | Asterisk | < 18.26.3 |
| Sangoma | Certified Asterisk | 18.9 |
Related Weaknesses (CWE)
References
- https://github.com/asterisk/asterisk/security/advisories/GHSA-v9q8-9j8m-5xwpExploitVendor Advisory
- https://lists.debian.org/debian-lts-announce/2025/10/msg00006.html
FAQ
What is CVE-2025-1131?
CVE-2025-1131 is a vulnerability with a CVSS score of 7.8 (HIGH). A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX envir...
How severe is CVE-2025-1131?
CVE-2025-1131 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-1131?
Check the references section above for vendor advisories and patch information. Affected products include: Sangoma Asterisk, Sangoma Certified Asterisk.