Skip to main content
RTC Security Newsletter

Curated VoIP and WebRTC security news, research and updates by Enable Security.

Subscribe

September 2026: Kamailio’s advisory gap, WeChat zero-click worm, Switchvox exploited

Published on Sep 30, 2026

September was a month of advisories, lots of them, from OpenSIPS, FreePBX, Janus, and others. It also had two stories about what happens when security fixes don’t reach the people who need them: Switchvox being exploited weeks after a patch that was only announced inside the admin portal, and Kamailio’s IMS bugs that will never get an advisory.

You’ll also notice that many advisories in this edition come without a CVE. About 40 GitHub security advisories covered here had no CVE ID when we put this issue together. GitHub, which normally assigns CVE IDs for advisories published there, has a long backlog, so IDs are arriving weeks or months late. Other organisations such as VulnCheck, MITRE and VulDB are filling the gap, with descriptions and scores that don’t always match the project’s advisory. If your patching process relies on CVE IDs, it’s missing a lot right now.

In this edition, we cover:

  • coturn guide refresh: our security configuration guide now covers 4.18.0, including a fix to our own TLS-only advice
  • FreeSWITCH api-chat: why enabling authentication doesn’t close the hole
  • Kamailio’s Diameter and IMS bugs: why they won’t get security advisories, and why “secure environments” is not a security boundary
  • WeWorm: the zero-click WeChat call bug, and the caveats most of the coverage left out
  • Sangoma Switchvox: exploited in the wild, and a patch announcement you could only see after logging in
  • OpenSIPS: sixteen advisories in two batches, plus short news on Issabel, Janus, pjproject, FreePBX, Pexip and more

The RTCSec newsletter is a free periodic newsletter bringing you commentary and news around VoIP and WebRTC security. We cover both defensive and offensive security as they relate to Real-time Communications.

What is RTC security anyway? Real-time communications security determines if you can safely communicate in real time - whether it be with other humans or machines.

You may sign up to receive the RTCSec newsletter here. If you like what we’re doing, you’re most welcome to:

  • Forward it to those who may find this newsletter particularly fruitful.
  • Let us know if there are any RTC security news items we should cover.

To view past issues, please visit our website at https://www.enablesecurity.com/newsletter/.


Our news

Refreshed the coturn security configuration guide through 4.18.0, and fixed our own TLS-only advice

I updated our coturn security configuration guide to cover everything up to 4.18.0. Since the June refresh, coturn has shipped 4.15 through 4.18, mostly security fixes.

The most important fix was to our own advice. The guide said no-udp gives you a TCP/TLS-only server that spoofed reflection traffic cannot reach. But before 4.17.0, coturn turned DTLS on by itself whenever it found a valid certificate and key, so setting up TLS also opened a DTLS listener that no-udp left running. On 4.16.x and older, add no-dtls. From 4.17.0, DTLS is off unless you add dtls.

If you’re upgrading, watch for:

  • no-dtls and no-cli were removed in 4.18.0, so drop them from your config
  • The log format changed in both 4.17.0 and 4.18.0, which will break log parsers and alert rules
  • Stateless nonces are on by default from 4.17.0; load-balanced setups want a shared stateless-nonce-secret

FreeSWITCH api-chat: registered users can exploit it too

In August, I linked the api-chat takeovers to outdated FreeSWITCH installations that still accept unauthenticated SIP MESSAGE requests (CVE-2021-37624). That understated the problem. In versions up to and including 1.11.2, anyone whose MESSAGE requests FreeSWITCH accepts can address one to sip:api+<command>@..., and FreeSWITCH will run <command> as an API command. Those commands include system, which runs OS commands.

Enabling authentication does not close this off: any registered user or trusted peer can still do it. So one compromised SIP account, such as a phone with a weak or leaked password, is enough to take over the whole server.

Upgrade to 1.11.3, which places api-chat behind a new enable-chat-api-proto setting that is off by default (PR #3135 for mod_sofia, PR #3136 for mod_verto). Then leave that setting off.

Kamailio’s Diameter and IMS bugs: why you won’t get an advisory for them

Kamailio had a wave of memory-safety reports in its CDP (Diameter) and IMS modules over the last few weeks, several of them LLM-assisted. We reproduced both CDP bugs in our lab. None of them came with a Kamailio security advisory, and that is by design.

Kamailio’s security policy covers 128 modules. Everything else, including CDP, the IMS modules and lrkproxy, is handled as an ordinary public bug, on the reasoning that CDP and IMS run in secure environments with “trusted and certified UAs”. On #4876, maintainer Henning Westerholt said reports have multiplied with LLM tools, which is why the project narrowed its security process to a list of modules earlier this year. CDP isn’t on that list.

That “secure environments” argument is the old telecom walled garden. The trusted UAs are subscribers’ phones, and in some networks a handset on the IMS APN gets direct IP access to the IMS core. The #4876 overflow even happens before any Diameter peer is identified. If you run these modules, don’t expect an advisory: watch the public issues yourself and treat your network perimeter as the security boundary.

What to fix:

  • CDP (#4876, #4909): fixed in Kamailio 6.0.8; there is no fixed 6.1 release yet, so 6.1 needs a branch build. Restrict network access to the Diameter acceptor and keep AcceptUnknownPeers off.
  • lrkproxy (#4920, #4957): one overflow is only partly fixed and another is still open. Disable it or keep untrusted SIP away from it.
  • The IMS registrar and ims_qos_npn modules have overflows too (#4886, #4954, #4953).

What’s happening?

WeWorm: a zero-click bug in WeChat’s VoIP stack, and the caveats

On 8 September Calif published WeWorm, a demo worm that spreads through WeChat voice calls on Android and iOS. Calif is Thai Duong’s company (BEAST, CRIME and POODLE). Calif’s post and the coverage lead with “a billion phones” and an AI-built worm. The finding is serious, but the caveats in Calif’s own post mostly didn’t make it into the coverage.

What they actually say:

  • The bug: memory corruption in WeChat’s VoIP stack. No other details, no CVE. The write-up is kept for an upcoming conference.
  • Zero-click, before the answer: the exploit fires while the phone is still ringing. Answering doesn’t matter, and declining only stops that attempt.
  • Impact: code execution inside WeChat, which means full control of the account (read and send messages, place calls). Taking over the device needs other Android and iOS bugs chained on top, so “a billion phones” really means a billion accounts.
  • Precondition: the attacker has to be on the victim’s friend list. Calif’s answer is that you compromise a friend first, which is exactly what the worm does: the attacker calls a victim, and the victim’s account calls the next victim.
  • AI: they say AI found the bug and helped write the first exploit in about two days.

The worm is a demo with three phones, and the code was never released. The demo video shows the attacker’s Android phone taking over an iPhone’s WeChat while it rings, and the hijacked iPhone then doing the same to a second Pixel. Tencent fixed it in Android 8.0.77 and iOS 8.0.76 on 21 August, blocked it server-side by 28 August, and told The Register it has “no evidence that the issue was exploited”. Also in Calif’s timeline: their WeChat accounts were banned for four days, the day after they reported the bug. We’ve seen this before: Yealink banned the RPS account of the researchers who reported its provisioning flaws in 2025.

The part that matters for RTC: call setup is attack surface that requires no user interaction. The client parses what the caller sends before the user has decided anything, which is how NSO exploited WhatsApp too. We look forward to the talk!

Sangoma Switchvox: CVE-2026-9586 exploited in the wild 47 days after the patch

The critical Switchvox SMB bug from Cameron Lischke’s advisories we covered in July, an unauthenticated SQL injection in the /pa endpoint (CVE-2026-9586, CVSS 9.3), is now being exploited. Sangoma has an open incident for on-premises systems (cloud instances are not affected) and says exposed systems were at risk “regardless of password strength”. The fix shipped in 8.4.0.2 on 14 July.

The vulnerable query runs as the PostgreSQL superuser, so one request gets a shell via COPY TO PROGRAM. Horizon3’s honeypots were hit exactly this way on 30 August, as Zach Hanley’s team describes in its disclosure, and CISA added the CVE to KEV on 2 September. To check whether you were hit, look for injected SQL in /var/log/switchvox/db-quirks.log.

Upgrading does not clean a compromised box. Restore a snapshot or backup from before 28 August and then upgrade, or do a clean install of 8.4.0.2, and close the admin and user portals and APIs to untrusted networks first. Some operators on the Outages mailing list said they found backdoors in backup files, so a recent backup may not be safe either.

The real failure is how the fix was announced: a banner in the admin portal, shown only after login. A notification that you only see once you log in to the system that is being exploited is not much of a notification.

OpenSIPS: sixteen advisories in two batches

OpenSIPS published five advisories on 7 September and eleven on 28 September, none with a CVE yet. Almost all are in specific modules, so what matters is whether your script loads them. Upgrade to 4.0.2 or 3.6.9 (tagged 8 September).

It’s interesting to see OpenSIPS publish advisories even for niche modules, while Kamailio keeps many of its modules out of its security process.

Răzvan Crainea wrote the fixes and published the advisories. Credited reporters: Tristan Madani (Talence Security), Jace, tinkerFz (Tencent Keen Security Lab), Bin Luo, Nikola Kojic (RAS-IT) and David Korczynski (Ada Logics).

Short news

Kamailio’s default config now drops all SIP until you turn it on

Daniel-Constantin Mierla changed the default kamailio.cfg in master so a fresh install drops all SIP until you define ACTIVE, WITH_AUTH or WITH_IPAUTH, instead of routing traffic with no authentication. ACTIVE came first, and a follow-up commit the same evening added WITH_AUTH and WITH_IPAUTH. Master only for now, no backport to 6.0 or 6.1.

Issabel’s hard-coded pbxapi JWT key is being exploited for RCE (CVE-2026-89026)

Issabel’s /pbxapi REST API shipped with the same JWT signing key on every install, so anyone can forge a token and run OS commands through Asterisk (CVE-2026-89026). Issabel’s fix commit of 31 July says the key had already leaked and was used to install malware. A 2018 attempt to randomise the key per install didn’t work, because the value was fixed at package build time. Update issabel-framework to 5.0.0-4 or 4.0.0-13, check for signs of compromise and keep /pbxapi off the internet. Thanks to Fred Posner for the pointer.

FreeSWITCH: SDP-less re-INVITE gets an RTP/AVP offer despite rtp_secure_media=mandatory

An open bug report shows FreeSWITCH 1.11.2 and 1.11.3 answering an SDP-less re-INVITE on an SRTP call with a plain RTP/AVP offer, even with rtp_secure_media=mandatory. Whether media actually goes unencrypted depends on the peer. No maintainer response yet.

pjproject: four medium advisories, and a CVE for the NUL-in-SAN bypass

Four medium advisories on 17 September, found by Anthropic using Claude. None of the fixes are in a release yet (2.17 is still the latest).

FreePBX: ten more advisories across two batches

Ten more advisories on 17 and 29 September, none with CVEs. The ones worth acting on:

  • An ordinary UCP user can read the whole database, including password hashes, via SQL injection (GHSA-3827-8r8q-362j, sangomartapi 16.0.57 / 17.0.29).
  • An ordinary UCP user gets RCE through AMI injection in a call-forward number (GHSA-3hr3-9whj-655f, framework 16.0.50 / 17.0.33).
  • An outside caller who controls their Caller ID can plant stored XSS in CEL Reports (GHSA-hq6g-xv43-3v87, cel 16.0.21 / 17.0.3).

Pexip Infinity: unauthenticated RCE on Conferencing Nodes and crafted-media memory corruption

Pexip’s July security bulletins, all reported by Oddmund Skogen and fixed in 38.2, 39.2, 40.1 and 41.0:

HP’s Poly PrivateConnect runs Pexip and has its own advisory.

Microsoft Teams: removed participants can keep listening via ACS Call Automation

Jacob Greenway reports that Azure Communication Services can attach a separate session to a Teams meeting using only its serverCallId, which any participant can get. That session keeps receiving audio and roster updates after the organiser removes the attacker. It needs the lobby off. Reported to MSRC on 19 August with no response beyond an automated reply, no CVE and no independent confirmation yet (PoC).

Browser WebRTC fixes: Chrome 152 point release, Chrome 153 and Firefox 156

A follow-up to August’s Chrome 152 bullet.

Janus: six advisories, fixed in 1.4.2 and 0.16.2

Six advisories on 23 September, fixed in 1.4.2 and 0.16.2, none with CVEs. This follows the 1.4.1 fixes we covered in May.

mediasoup: one SCTP peer can crash the whole worker

A high-severity SCTP advisory on 16 September (GHSA-rq7g-r9qr-rwpq): any peer with an established association, such as a WebRTC data channel, can crash the whole worker and every session on it. Fixed in 3.27.1 (Rust 0.28.1), or set enablePartialReliability to false. It’s the third batch of mediasoup SCTP bugs since June, following the ones we covered in June and July.

GStreamer: RTP and RTSP denial-of-service fixes

GStreamer sits in a lot of RTC pipelines. Three recent advisories are network-reachable denial of service:

  • H.264 and H.265 RTP depayloaders don’t cap reassembled fragments, so a sender can exhaust memory (CVE-2026-18649, gst-plugins-good 1.28.6).
  • RTP sessions create an entry for every new SSRC and CSRC with no limit, so valid RTP alone can exhaust memory (SA-2026-0074, gst-plugins-good 1.28.6).
  • A crafted RTSP Authorization header crashes an RTSP server (CVE-2026-85150, gst-plugins-base 1.28.7).

libsrtp 2.8.1 lets applications require cryptex

libsrtp v2.8.1 adds srtp_set_stream_require_cryptex() from Philipp Hancke, so applications can reject packets whose header extensions arrive unprotected. Until now, cryptex could be used but not enforced. We covered cryptex landing in libsrtp in March 2025.

SIPSorcery: two more DoS advisories, no fix yet

Two more advisories on 20 September, no CVEs, and no fix: 10.0.16, the latest release, is affected. This follows our July and August coverage.

  • High: one malformed packet relayed through a turns: or stuns: ICE server permanently kills the TURN relay path (GHSA-6848-qmp4-652w).
  • Medium: an oversized Content-Length makes the SIP-over-WebSocket client loop at 100% CPU (GHSA-j5j8-rhcm-7fp9).

SIPp 3.7.8 fixes three remotely triggered buffer overflows

SIPp 3.7.8 (23 September) fixes three buffer overflows reported by Tristan Madani. A malicious peer can crash SIPp through 3.7.7 with:

SIPp is a test tool, so this matters for test rigs exposed to untrusted SIP traffic.

sngrep: another stack overflow in SIP header handling, fixed on master only

A long Call-ID, X-Call-ID or Reason header overflows a stack buffer in sngrep through 1.8.4, whether it comes from a pcap, live capture or HEP (CVE-2026-90558). It’s a different code path from the overflows we covered in April 2024. The fix is on master, with no release yet.

Matrix: an Element Web preview bug and a Continuwuity account takeover

Two Matrix advisories on 2 September, neither with a CVE:

  • High, Continuwuity (homeserver): the password reset flow emailed the reset link to an address the requester chose, so any account with an email address could be taken over (GHSA-v2x6-m99h-vqxx). Only servers with SMTP configured; fixed in 26.7.3.
  • Low, Element Web and Desktop: some URL preview links could run JavaScript, behind an experimental flag that is off by default (GHSA-9r5h-8m2x-w7q6). Fixed in 1.12.27.

Zoom checks which other apps are using your microphone

Xusheng Li reverse engineered how Zoom’s My Notes feature knows you’re on a Google Meet, Teams or Slack call: it reads the macOS system log and a Windows registry key that show which apps are using the microphone. Neither needs microphone permission or elevated privileges, so any unprivileged process can do the same.

EtherHiding campaign opens a WebRTC data channel to its C2 without signaling

Netskope reports that a variant of the EtherHiding campaign on compromised websites now fetches code over a WebRTC data channel. The C2’s connection details are hardcoded in the script, so the browser connects straight to the attacker over UDP with no signaling server or STUN/TURN. It follows TWINLOOT’s use of Teams TURN servers in August. An HTTP proxy won’t see this traffic.

whitelist-bypass: tunnelling traffic through video-call SFUs

An open source tool for getting around Russia’s whitelist censorship: it tunnels internet traffic through the SFUs of approved Russian video-calling services such as VK Call and Yandex Telemost, over a WebRTC data channel or inside a VP8 video track. To DPI it looks like a normal call. For the services it supports, anyone who can start a call can repurpose the conferencing infrastructure as a relay. Via Tsahi Levent-Levi’s WebRTC Weekly.

Twilio WebSocket endpoints are anonymous unless you make them otherwise

Brent Bailey, who commits from a Twilio address, published a guide (in a personal repo, not official Twilio docs) on securing the wss:// endpoints behind ConversationRelay and Media Streams. By default anyone who finds the URL gets an anonymous channel into your voice AI agent. The fix: verify X-Twilio-Signature on the upgrade request and add short-lived, single-use tokens bound to the call. One gotcha: Twilio signs the WebSocket (wss) form of the URL, not the https one.

EU Cyber Resilience Act reporting obligations are now live

Since 11 September, manufacturers selling products with digital elements in the EU must report actively exploited vulnerabilities and severe incidents: an early warning within 24 hours, a notification within 72 hours, and a final report later. They must also tell affected users what to do. That includes IP PBX, SBC, phone and conferencing vendors. Switchvox’s “banner after login” notification this month is the kind of practice the CRA is aimed at.

SharkFest'26 EU: WebRTC network analysis masterclass

Robert Hess and Alexander Müller are running a one-day WebRTC network analysis masterclass on 2 November in Brussels, before SharkFest'26 EUROPE. It works through real captures (signaling, ICE/STUN/TURN, media) and covers what breaks WebRTC in enterprise networks and how Teams, Zoom, Webex and Meet differ. Attendees can bring their own captures.


Thanks to Vulners and other third parties for providing vulnerability source material.

This newsletter was prepared by Sandro Gauci and the Enable Security team for RTCSec newsletter subscribers. If you have someone in mind who would benefit from our content, please share.

To subscribe: here

Subscribe to Updates

Stay updated with our latest security insights and updates.

We hate spam and are committed to protecting and respecting your privacy. You can unsubscribe from our communications at any time. By subscribing, you are agreeing to the Privacy Policy.