High severity7.8NVD Advisory· Published Sep 23, 2025· Updated Jun 17, 2026
CVE-2025-1131
CVE-2025-1131
Description
A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions.
Non-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
29cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*+ 25 more
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1-rc1:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert10:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert11:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert12:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert13:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert14:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert15:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert6:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert7:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc1:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8-rc2:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert8:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:18.9:cert9:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc1:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1-rc2:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert1:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert2:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert3:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert4:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert5:*:*:*:*:*:*
- cpe:2.3:a:sangoma:certified_asterisk:20.7:cert6:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.