PT-2025-47479 · Audiocodes · Audiocodes Fax Server+1

·

CVE-2025-34330

·

Published

2025-11-19

·

Updated

2025-11-19

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description The web administration component (F2MAdmin) includes an unauthenticated prompt upload endpoint at /AudioCodes files/utils/IVR/diagram/ajaxPromptUploadFile.php. This script accepts uploaded files and writes them to the C:F2MAdmintmp directory using a filename derived from application constants, without authentication, authorization, or file-type validation. An unauthenticated remote attacker can upload or overwrite prompt- or music-on-hold–related files, potentially tampering with IVR audio content or preparing files for further attacks.
Recommendations Versions prior to 2.6.23 should be updated.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34330

Affected Products

Audiocodes Fax Server
Auto-Attendant Ivr