Unauthenticated File Upload Vulnerability in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34330

6.9MEDIUM

Key Information:

Vendor
CVE Published:
19 November 2025

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2025-34330?

The AudioCodes Fax Server and Auto-Attendant IVR appliances have a significant security issue due to the presence of an unauthenticated prompt upload endpoint within the web administration component, F2MAdmin. This endpoint lacks proper authentication, allowing attackers to upload or overwrite audio files related to IVR prompts and music-on-hold directly into a specified directory. This capability can lead to unauthorized tampering with IVR audio content and paves the way for further malicious activities, especially if manipulated files are prepared for future exploitation. To mitigate this risk, users are advised to apply the latest patches and security updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AudioCodes Fax/IVR Appliance 0 <= 2.6.23

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.