PT-2025-47478 · Audiocodes · Auto-Attendant Ivr+1

Pierre Barre

·

Publicado

2025-11-19

·

Atualizado

2025-11-20

·

CVE-2025-34329

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description The software contains an unauthenticated backup upload endpoint located at /AudioCodes files/ajaxBackupUploadFile.php within the F2MAdmin web interface. The script determines a backup folder path from the application configuration, creates the directory if it doesn't exist, and then moves an uploaded file to that location using the attacker-controlled filename, without any authentication, authorization, or file-type validation. On default Windows deployments where the backup directory resolves to the system drive, a remote attacker can upload web server or interpreter configuration files. This can cause a log file or other server-controlled resource to be treated as executable code, allowing subsequent HTTP requests to trigger arbitrary command execution under the web server account, which runs as NT AUTHORITYSYSTEM.
Recommendations Versions prior to 2.6.23 should be updated.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-34329

Produtos afetados

Audiocodes Fax Server
Auto-Attendant Ivr