PT-2025-47479 · Audiocodes · Audiocodes Fax Server+1

Pierre Barre

·

Published

2025-11-19

·

Updated

2025-11-19

·

CVE-2025-34330

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description The web administration component (F2MAdmin) includes an unauthenticated prompt upload endpoint at /AudioCodes files/utils/IVR/diagram/ajaxPromptUploadFile.php. This script accepts uploaded files and writes them to the C:F2MAdmintmp directory using a filename derived from application constants, without authentication, authorization, or file-type validation. An unauthenticated remote attacker can upload or overwrite prompt- or music-on-hold–related files, potentially tampering with IVR audio content or preparing files for further attacks.
Recommendations Versions prior to 2.6.23 should be updated.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-34330

Affected Products

Audiocodes Fax Server
Auto-Attendant Ivr