Asterisk remotely exploitable leak of RTP UDP ports and internal resources
Vulnerability Description
Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54995
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/asterisk/asterisk/security/advisories/GHSA-557q-795j-wfx2
- https://github.com/asterisk/asterisk/pull/1405
- https://github.com/asterisk/asterisk/pull/1406
- https://github.com/asterisk/asterisk/commit/0278f5bde14565c6838a6ec39bc21aee0cde56a9
- https://github.com/asterisk/asterisk/commit/eafcd7a451dcd007dddf324ac37dd55a4808338d
More from asterisk
View All →Affected Vendor
asterisk
View all reports →