CVE Feed

    Dashboard / CVE / CVE-2025-34329

    CVE-2025-34329

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFile.php in the F2MAdmin web interface. The script derives a backup folder path from application configuration, creates the directory if it does not exist, and then moves an uploaded file to that location using the attacker-controlled filename, without any authentication, authorization, or file-type validation. On default Windows deployments where the backup directory resolves to the system drive, a remote attacker can upload web server or interpreter configuration files that cause a log file or other server-controlled resource to be treated as executable code. This allows subsequent HTTP requests to trigger arbitrary command execution under the web server account, which runs as NT AUTHORITY\\SYSTEM.

    Published:Nov 19, 2025
    Last Modified:Dec 12, 2025
    EPS:Nov 19, 2025
    EPSS Score:0.0107
    CVSS Score:9.8

    Affected Products

    Vendor
    Audiocodes
    Product
    Fax\/ivr
    Vendor
    Audiocodes
    Product
    Fax Server
    Vendor
    Audiocodes
    Product
    Interactive Voice Response

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High