CVE-2021-45461General(sangoma / freepbx)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.

0.0/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • freepbx
  • pbxact
  • restapps

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
freepbxpbxactrestapps

5 versions affected across 3 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-02: 102-02
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • transilienceai@transilienceai
    General

    @__kokumoto **攻撃者の背景**: INJ3CTOR3は2020年のCVE-2019-19006、2022年のElastix(CVE-2021-45461)攻撃で知られ、VoIPシステムを繰り返し標的にしています🎯 #ThreatActor

    Post summary

    The tweet references two CVEs associated with a threat actor but offers no technical, exploit, or mitigation details.

    1000050
    317 followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appsangomafreepbx---
Appsangomapbxact---
Appsangomarestapps15.0.19.87--
Appsangomarestapps15.0.19.88--
Appsangomarestapps16.0.18.40--
Appsangomarestapps16.0.18.41--

Explore more