PT-2025-47478 · Audiocodes · Auto-Attendant Ivr+1
Pierre Barre
·
Published
2025-11-19
·
Updated
2025-11-20
·
CVE-2025-34329
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description
The software contains an unauthenticated backup upload endpoint located at
/AudioCodes files/ajaxBackupUploadFile.php within the F2MAdmin web interface. The script determines a backup folder path from the application configuration, creates the directory if it doesn't exist, and then moves an uploaded file to that location using the attacker-controlled filename, without any authentication, authorization, or file-type validation. On default Windows deployments where the backup directory resolves to the system drive, a remote attacker can upload web server or interpreter configuration files. This can cause a log file or other server-controlled resource to be treated as executable code, allowing subsequent HTTP requests to trigger arbitrary command execution under the web server account, which runs as NT AUTHORITYSYSTEM.Recommendations
Versions prior to 2.6.23 should be updated.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Audiocodes Fax Server
Auto-Attendant Ivr