---
cve: "CVE-2021-45461"
severity: "LOW"
cvss: 3.1
epss: "21.7%"
vendor: "n/a"
kev: false
exploited: false
published: "2021-12-22 19:15:11"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T00:50:12+02:00"
---

# CVE-2021-45461

> 3.1 LOW

## Beschreibung

FreePBX, when restapps (aka Rest Phone Apps) 15.0.19.87, 15.0.19.88, 16.0.18.40, or 16.0.18.41 is installed, allows remote attackers to execute arbitrary code, as exploited in the wild in December 2021. The fixed versions are 15.0.20 and 16.0.19.

## Referenzen

- <https://community.freepbx.org/t/0-day-freepbx-exploit/80092>
- <https://community.freepbx.org/t/security-issue-potential-rest-phone-apps-rce/80109>
- <https://wiki.freepbx.org/display/FOP/2021-12-21+SECURITY%3A+Potential+Rest+Phone+Apps+RCE>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-45461) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
