Unauthenticated File Upload Vulnerability in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34330
Key Information:
- Vendor
Audiocodes Limited
- Vendor
- CVE Published:
- 19 November 2025
Badges
What is CVE-2025-34330?
The AudioCodes Fax Server and Auto-Attendant IVR appliances have a significant security issue due to the presence of an unauthenticated prompt upload endpoint within the web administration component, F2MAdmin. This endpoint lacks proper authentication, allowing attackers to upload or overwrite audio files related to IVR prompts and music-on-hold directly into a specified directory. This capability can lead to unauthorized tampering with IVR audio content and paves the way for further malicious activities, especially if manipulated files are prepared for future exploitation. To mitigate this risk, users are advised to apply the latest patches and security updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AudioCodes Fax/IVR Appliance 0 <= 2.6.23
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
