Unauthenticated File Upload Vulnerability in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34330

6.9MEDIUM

What is CVE-2025-34330?

The AudioCodes Fax Server and Auto-Attendant IVR appliances have a significant security issue due to the presence of an unauthenticated prompt upload endpoint within the web administration component, F2MAdmin. This endpoint lacks proper authentication, allowing attackers to upload or overwrite audio files related to IVR prompts and music-on-hold directly into a specified directory. This capability can lead to unauthorized tampering with IVR audio content and paves the way for further malicious activities, especially if manipulated files are prepared for future exploitation. To mitigate this risk, users are advised to apply the latest patches and security updates.

Affected Version(s)

AudioCodes Fax/IVR Appliance 0 <= 2.6.23

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34330 : Unauthenticated File Upload Vulnerability in AudioCodes Fax Server and Auto-Attendant IVR Appliances