PT-2025-47478 · Audiocodes · Auto-Attendant Ivr+1
Pierre Barre
·
Publicado
2025-11-19
·
Atualizado
2025-11-20
·
CVE-2025-34329
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description
The software contains an unauthenticated backup upload endpoint located at
/AudioCodes files/ajaxBackupUploadFile.php within the F2MAdmin web interface. The script determines a backup folder path from the application configuration, creates the directory if it doesn't exist, and then moves an uploaded file to that location using the attacker-controlled filename, without any authentication, authorization, or file-type validation. On default Windows deployments where the backup directory resolves to the system drive, a remote attacker can upload web server or interpreter configuration files. This can cause a log file or other server-controlled resource to be treated as executable code, allowing subsequent HTTP requests to trigger arbitrary command execution under the web server account, which runs as NT AUTHORITYSYSTEM.Recommendations
Versions prior to 2.6.23 should be updated.
Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Audiocodes Fax Server
Auto-Attendant Ivr