CVE Feed

    Dashboard / CVE / CVE-2025-34330

    CVE-2025-34330

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/utils/IVR/diagram/ajaxPromptUploadFile.php. The script accepts an uploaded file and writes it into the C:\\F2MAdmin\\tmp directory using a filename derived from application constants, without any authentication, authorization, or file-type validation. A remote, unauthenticated attacker can upload or overwrite prompt- or music-on-hold–related files in this directory, potentially leading to tampering with IVR audio content or preparing files for use in further attacks.

    Published:Nov 19, 2025
    Last Modified:Dec 12, 2025
    EPS:Nov 19, 2025
    EPSS Score:0.00238
    CVSS Score:5.3

    Affected Products

    Vendor
    Audiocodes
    Product
    Fax\/ivr
    Vendor
    Audiocodes
    Product
    Fax Server
    Vendor
    Audiocodes
    Product
    Interactive Voice Response

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High