CVE-2025-1131
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-09-23
Last updated on: 2025-11-03
Assigner: Gridware
Description
Description
A local privilege escalation vulnerability exists in the safe_asterisk script included with the Asterisk toolkit package. When Asterisk is started via this script (common in SysV init or FreePBX environments), it sources all .sh files located in /etc/asterisk/startup.d/ as root, without validating ownership or permissions.
Non-root users with legitimate write access to /etc/asterisk can exploit this behaviour by placing malicious scripts in the startup.d directory, which will then execute with root privileges upon service restart.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sangoma | asterisk | to 18.26.3 (exc) |
| sangoma | asterisk | From 20.0.0 (inc) to 20.15.1 (exc) |
| sangoma | asterisk | From 21.0.0 (inc) to 21.10.1 (exc) |
| sangoma | asterisk | From 22.0.0 (inc) to 22.5.1 (exc) |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 18.9 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
| sangoma | certified_asterisk | 20.7 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-427 | The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors. |