CVE-2025-49832 | Asterisk PBX up to 18.26.2/20.7-cert6/20.15.0/21.10.0/22.5.0 verification.c null pointer dereference (GHSA-mrq5-74j5-f5cr / WID-SEC-2025-1697)
A vulnerability was found in Asterisk PBX up to 18.26.2/20.7-cert6/20.15.0/21.10.0/22.5.0 and classified as problematic. This issue affects some unknown processing of the file Asterisk/res/res_stir_shaken/verification.c. The manipulation leads to null pointer dereference.
The identification of this vulnerability is CVE-2025-49832. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.