CVE-2025-49832 | Asterisk PBX up to 18.26.2/20.7-cert6/20.15.0/21.10.0/22.5.0 verification.c null pointer dereference (GHSA-mrq5-74j5-f5cr / WID-SEC-2025-1697)
A vulnerability was found in Asterisk PBX up to 18.26.2/20.7-cert6/20.15.0/21.10.0/22.5.0 and classified as problematic. Impacted is an unknown function of the file Asterisk/res/res_stir_shaken/verification.c. Executing a manipulation can lead to null pointer dereference.
This vulnerability is tracked as CVE-2025-49832. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.