Sploitus

CVE-2025-34333

1 known exploit for CVE-2025-34333

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT AUTHORITY\\SYSTEM. As a result, any local user can create or alter server-side scripts within the webroot and then trigger them via HTTP requests, causing arbitrary code to execute with SYSTEM privileges.

Audiocodes Fax Server
≤ 2.6.23
Audiocodes Interactive Voice Response
≤ 2.6.23
Fix
Available
CVSS 4.0
8.5 HIGH
CVSS 3.1
7.8 HIGH
EPSS
0.2% (10th percentile)
Weakness
CWE-276
NVD status
Analyzed
Published
2025-11-19
CVE-2025-34333 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-34333

Proof-of-concept code and exploit modules indexed by Sploitus