CVE-2021-45461 is a critical remote code execution vulnerability affecting FreePBX and PBXact systems running specific versions of the restapps module (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41). With a CVSS score of 9.8, it allows unauthenticated attackers to execute arbitrary code with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. This vulnerability was actively exploited in the wild in December 2021, as evidenced by media reports detailing campaigns installing PHP web shells on Elastix VoIP systems. While no public exploit code is readily available, the high community discussion and media coverage indicate significant attention to this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.0.19.87CPE matchmatch criteria | cpe:2.3:a:sangoma:restapps:15.0.19.87:*:*:*:*:*:*:* | ||
15.0.19.88CPE matchmatch criteria | cpe:2.3:a:sangoma:restapps:15.0.19.88:*:*:*:*:*:*:* | ||
16.0.18.40CPE matchmatch criteria | cpe:2.3:a:sangoma:restapps:16.0.18.40:*:*:*:*:*:*:* | ||
16.0.18.41CPE matchmatch criteria | cpe:2.3:a:sangoma:restapps:16.0.18.41:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.