CVE-2025-54995 - CVE House
Back to Database
Status published Medium CVE-2025-54995

Asterisk remotely exploitable leak of RTP UDP ports and internal resources

Vulnerability Description

Asterisk is an open source private branch exchange and telephony toolkit. Prior to versions 18.26.4 and 18.9-cert17, RTP UDP ports and internal resources can leak due to a lack of session termination. This could result in leaks and resource exhaustion. This issue has been patched in versions 18.26.4 and 18.9-cert17.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-54995

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

asterisk
Vulnerable Versions:
< 18.26.4, < 18.9-cert17

Timeline

Official Publish: August 28th, 2025
Last Modified: November 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Weaknesses (CWE)