CVE-2025-34330

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated prompt upload endpoint at AudioCodes_files/utils/IVR/diagram/ajaxPromptUploadFile.php. The script accepts an uploaded file and writes it into the C:\\F2MAdmin\\tmp directory using a filename derived from application constants, without any authentication, authorization, or file-type validation. A remote, unauthenticated attacker can upload or overwrite prompt- or music-on-hold–related files in this directory, potentially leading to tampering with IVR audio content or preparing files for use in further attacks.
CVSS

No CVSS.

Configurations

No configuration.

History

19 Nov 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-19 17:15

Updated : 2025-11-19 19:14


NVD link : CVE-2025-34330

Mitre link : CVE-2025-34330

CVE.ORG link : CVE-2025-34330


JSON object : View

Products Affected

No product.

CWE
CWE-434

Unrestricted Upload of File with Dangerous Type