CVE-2025-34328
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint at AudioCodes_files/utils/IVR/diagram/ajaxScript.php. The saveScript action writes attacker-supplied data directly to a server-side file path under the privileges of the web service account, which runs as NT AUTHORITY\\SYSTEM on Windows deployments. A remote, unauthenticated attacker can write arbitrary files into the product’s web-accessible directory structure and subsequently execute them.
- Affected products
- Audiocodes Fax Server, Auto-Attendant Ivr
- Audiocodes Fax Server
- ≤ 2.6.23
- Audiocodes Interactive Voice Response
- ≤ 2.6.23
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 0.7% (51th percentile)
- Weakness
- CWE-434
- NVD status
- Analyzed
- Published
- 2025-11-19
CVE-2025-34328 at NVD
1 known exploit for CVE-2025-34328
Proof-of-concept code and exploit modules indexed by Sploitus