PT-2025-47478 · Audiocodes · Auto-Attendant Ivr+1

Pierre Barre

·

Published

2025-11-19

·

Updated

2025-11-20

·

CVE-2025-34329

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description The software contains an unauthenticated backup upload endpoint located at /AudioCodes files/ajaxBackupUploadFile.php within the F2MAdmin web interface. The script determines a backup folder path from the application configuration, creates the directory if it doesn't exist, and then moves an uploaded file to that location using the attacker-controlled filename, without any authentication, authorization, or file-type validation. On default Windows deployments where the backup directory resolves to the system drive, a remote attacker can upload web server or interpreter configuration files. This can cause a log file or other server-controlled resource to be treated as executable code, allowing subsequent HTTP requests to trigger arbitrary command execution under the web server account, which runs as NT AUTHORITYSYSTEM.
Recommendations Versions prior to 2.6.23 should be updated.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-34329

Affected Products

Audiocodes Fax Server
Auto-Attendant Ivr