Authenticated Command Injection in AudioCodes Fax Server and Auto-Attendant IVR Appliances
CVE-2025-34334

8.7HIGH

Key Information:

Vendor
CVE Published:
19 November 2025

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2025-34334?

The AudioCodes Fax Server and Auto-Attendant IVR appliances are susceptible to an authenticated command injection vulnerability through the fax test functionality. When an authenticated user initiates a 'send' fax test, the system constructs a command line that includes parameters supplied by the user, passing it to a backend process without adequate validation or sanitization. This flaw allows attackers with access to the fax test interface to inject arbitrary shell commands that may be executed with NT AUTHORITY\SYSTEM privileges. Additionally, the generated batch files are stored in a directory with insufficient security controls, permitting local low-privilege users to alter pending batch files to escalate their own privileges.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AudioCodes Fax/IVR Appliance 0 <= 2.6.23

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.