Unauthenticated Backup Upload Vulnerability in AudioCodes Fax Server and IVR Appliances
CVE-2025-34329
Key Information:
- Vendor
Audiocodes Limited
- Vendor
- CVE Published:
- 19 November 2025
Badges
What is CVE-2025-34329?
The AudioCodes Fax Server and Auto-Attendant IVR appliances up to version 2.6.23 are vulnerable due to an unauthenticated upload endpoint. This vulnerability enables attackers to upload files to the server, utilizing an attacker-controlled filename. The lack of authentication, authorization checks, and file type validation allows a remote attacker to exploit this flaw. In a default Windows deployment scenario, this can lead to significant risks, including arbitrary code execution, as it may allow essential server resources to be treated as executable code, potentially leading to severe system compromises.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AudioCodes Fax/IVR Appliance 0 <= 2.6.23
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
