PT-2025-47484 · Audiocodes · Auto-Attendant Ivr+2

Pierre Barre

·

Published

2025-11-19

·

Updated

2025-12-15

·

CVE-2025-34335

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23
Description The software contains a command injection issue within the license activation process, specifically in the ''ActivateLicense.php'' file located in the ''AudioCodes files'' directory. The application constructs a command for ''fax server lic cmdline.exe'' using a filename derived from a user-supplied license file upload. The file extension, which is controlled by the attacker, is incorporated into the command string without proper validation or sanitization. This allows an authenticated user to inject arbitrary shell commands that are executed with NT AUTHORITYSYSTEM privileges. The vulnerable parameter is the file extension within the uploaded license file.
Recommendations Versions prior to 2.6.23 should be used.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-34335

Affected Products

Audiocodes Fax Server
Auto-Attendant Ivr
Fax Server Lic Cmdline.Exe