Local File Access Vulnerability in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34333
Key Information:
- Vendor
Audiocodes Limited
- Vendor
- CVE Published:
- 19 November 2025
Badges
What is CVE-2025-34333?
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose a critical security flaw by configuring the web document root at C:\F2MAdmin\F2E with excessive file system permissions. This oversight allows authenticated local users to gain modify rights to the directory, while the web server operates under the NT AUTHORITY\SYSTEM account. Consequently, any local user can inject or modify server-side scripts within the webroot, executing them via HTTP requests, which results in the potential for arbitrary code execution with elevated privileges. This vulnerability highlights the importance of enforcing strict file system permissions in server environments to mitigate unauthorized access and execution risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
AudioCodes Fax/IVR Appliance 0 <= 2.6.23
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
