PT-2025-47484 · Audiocodes · Auto-Attendant Ivr+2
Pierre Barre
·
Published
2025-11-19
·
Updated
2025-12-15
·
CVE-2025-34335
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description
The software contains a command injection issue within the license activation process, specifically in the ''ActivateLicense.php'' file located in the ''AudioCodes files'' directory. The application constructs a command for ''fax server lic cmdline.exe'' using a filename derived from a user-supplied license file upload. The file extension, which is controlled by the attacker, is incorporated into the command string without proper validation or sanitization. This allows an authenticated user to inject arbitrary shell commands that are executed with NT AUTHORITYSYSTEM privileges. The vulnerable parameter is the file extension within the uploaded license file.
Recommendations
Versions prior to 2.6.23 should be used.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Audiocodes Fax Server
Auto-Attendant Ivr
Fax Server Lic Cmdline.Exe