CVE-2025-34330
19.11.2025, 17:15
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/utils/IVR/diagram/ajaxPromptUploadFile.php. The script accepts an uploaded file and writes it into the C:\\F2MAdmin\\tmp directory using a filename derived from application constants, without any authentication, authorization, or file-type validation. A remote, unauthenticated attacker can upload or overwrite prompt- or music-on-holdrelated files in this directory, potentially leading to tampering with IVR audio content or preparing files for use in further attacks.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration
References