PT-2025-47480 · Audiocodes · Audiocodes Fax Server+1
Pierre Barre
·
Published
2025-11-19
·
Updated
2025-11-19
·
CVE-2025-34331
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description
The software contains an unauthenticated file read issue through the
download.php script. The script exposes a file download mechanism without proper access control, enabling unauthenticated remote users to request files from the appliance using attacker-supplied path and filename parameters. While the application limits file extensions, sensitive backup archives can be retrieved, potentially exposing internal databases and credential hashes. Exploitation may lead to the disclosure of administrative password hashes and other sensitive configuration data. The vulnerable endpoint is /download.php and utilizes parameters such as filename and path to retrieve files.Recommendations
Versions prior to 2.6.23 should be updated.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Audiocodes Fax Server
Auto-Attendant Ivr