PT-2025-47479 · Audiocodes · Audiocodes Fax Server+1
Pierre Barre
·
Published
2025-11-19
·
Updated
2025-11-19
·
CVE-2025-34330
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description
The web administration component (F2MAdmin) includes an unauthenticated prompt upload endpoint at
/AudioCodes files/utils/IVR/diagram/ajaxPromptUploadFile.php. This script accepts uploaded files and writes them to the C:F2MAdmintmp directory using a filename derived from application constants, without authentication, authorization, or file-type validation. An unauthenticated remote attacker can upload or overwrite prompt- or music-on-hold–related files, potentially tampering with IVR audio content or preparing files for further attacks.Recommendations
Versions prior to 2.6.23 should be updated.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Audiocodes Fax Server
Auto-Attendant Ivr