Asterisk is an open-source private branch exchange (PBX). Prior to versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk, trying to disallow shell commands to be run via the Asterisk command line interface (CLI) by configuring cli_permissions.conf (e.g. with the config line deny=!*) does not work which could lead to a security risk. If an administrator running an Asterisk instance relies on the cli_permissions.conf file to work and expects it to deny all attempts to execute shell commands, then this could lead to a security vulnerability. Versions 18.26.2, 20.14.1, 21.9.1, and 22.4.1 of Asterisk and versions 18.9-cert14 and 20.7-cert5 of certified-asterisk fix the issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47780.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-78"
]
}{
"cpe": [
"cpe:2.3:a:sangoma:asterisk:*:*:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:*:*:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:-:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc1:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert2:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert3:*:*:*:*:*:*",
"cpe:2.3:a:sangoma:certified_asterisk:20.7:cert4:*:*:*:*:*:*"
],
"source": [
"CPE_RANGE",
"CPE_STRING"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "18.26.2"
},
{
"fixed": "18.9"
},
{
"introduced": "20.0.0"
},
{
"fixed": "20.14.1"
},
{
"introduced": "21.0.0"
},
{
"fixed": "21.9.1"
},
{
"introduced": "22.0.0"
},
{
"fixed": "22.4.1"
},
{
"introduced": "18.9-NA"
},
{
"last_affected": "18.9-NA"
},
{
"introduced": "18.9-cert1"
},
{
"last_affected": "18.9-cert1"
},
{
"introduced": "18.9-cert1\\-rc1"
},
{
"last_affected": "18.9-cert1\\-rc1"
},
{
"introduced": "18.9-cert10"
},
{
"last_affected": "18.9-cert10"
},
{
"introduced": "18.9-cert11"
},
{
"last_affected": "18.9-cert11"
},
{
"introduced": "18.9-cert12"
},
{
"last_affected": "18.9-cert12"
},
{
"introduced": "18.9-cert13"
},
{
"last_affected": "18.9-cert13"
},
{
"introduced": "18.9-cert2"
},
{
"last_affected": "18.9-cert2"
},
{
"introduced": "18.9-cert3"
},
{
"last_affected": "18.9-cert3"
},
{
"introduced": "18.9-cert4"
},
{
"last_affected": "18.9-cert4"
},
{
"introduced": "18.9-cert5"
},
{
"last_affected": "18.9-cert5"
},
{
"introduced": "18.9-cert6"
},
{
"last_affected": "18.9-cert6"
},
{
"introduced": "18.9-cert7"
},
{
"last_affected": "18.9-cert7"
},
{
"introduced": "18.9-cert8"
},
{
"last_affected": "18.9-cert8"
},
{
"introduced": "18.9-cert8\\-rc1"
},
{
"last_affected": "18.9-cert8\\-rc1"
},
{
"introduced": "18.9-cert8\\-rc2"
},
{
"last_affected": "18.9-cert8\\-rc2"
},
{
"introduced": "18.9-cert9"
},
{
"last_affected": "18.9-cert9"
},
{
"introduced": "20.7-cert1"
},
{
"last_affected": "20.7-cert1"
},
{
"introduced": "20.7-cert1\\-rc1"
},
{
"last_affected": "20.7-cert1\\-rc1"
},
{
"introduced": "20.7-cert1\\-rc2"
},
{
"last_affected": "20.7-cert1\\-rc2"
},
{
"introduced": "20.7-cert2"
},
{
"last_affected": "20.7-cert2"
},
{
"introduced": "20.7-cert3"
},
{
"last_affected": "20.7-cert3"
},
{
"introduced": "20.7-cert4"
},
{
"last_affected": "20.7-cert4"
}
]
}