PT-2025-47480 · Audiocodes · Audiocodes Fax Server+1

Pierre Barre

·

Published

2025-11-19

·

Updated

2025-11-19

·

CVE-2025-34331

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description The software contains an unauthenticated file read issue through the download.php script. The script exposes a file download mechanism without proper access control, enabling unauthenticated remote users to request files from the appliance using attacker-supplied path and filename parameters. While the application limits file extensions, sensitive backup archives can be retrieved, potentially exposing internal databases and credential hashes. Exploitation may lead to the disclosure of administrative password hashes and other sensitive configuration data. The vulnerable endpoint is /download.php and utilizes parameters such as filename and path to retrieve files.
Recommendations Versions prior to 2.6.23 should be updated.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-34331

Affected Products

Audiocodes Fax Server
Auto-Attendant Ivr