Asterisk remotely exploitable leak of RTP UDP ports and internal resources

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-54995?

CVE-2025-54995 is a vulnerability classified as Improper Validation of Syntactic Correctness of Input and Uncontrolled Resource Consumption, affecting asterisk (affected versions: < 18.26.4 and < 18.9-cert17). This vulnerability is rated Medium, with a CVSS score of 6.5. Public exploit code or evidence is available for this vulnerability, but that does not confirm exploitation in the wild.

Analyzing data...

Overview

Original source data

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.

Affected products and scope

The analysis could not be completed. The original vulnerability data remains available below.

Technical details

The analysis could not be completed. The original vulnerability data remains available below.

Exploitability

The analysis could not be completed. The original vulnerability data remains available below.

Technical impact

The analysis could not be completed. The original vulnerability data remains available below.

Business impact

The analysis could not be completed. The original vulnerability data remains available below.

Remediation

The analysis could not be completed. The original vulnerability data remains available below.

Detection

The analysis could not be completed. The original vulnerability data remains available below.
Sources (12)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan