High severity7.8NVD Advisory· Published Nov 19, 2025· Updated Jun 17, 2026
CVE-2025-34333
CVE-2025-34333
Description
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT AUTHORITY\\SYSTEM. As a result, any local user can create or alter server-side scripts within the webroot and then trigger them via HTTP requests, causing arbitrary code to execute with SYSTEM privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<=2.6.23+ 1 more
- (no CPE)range: <=2.6.23
- cpe:2.3:a:audiocodes:fax_server:*:*:*:*:*:*:*:*range: <=2.6.23
- Range: <=2.6.23
- Range: <=2.6.23
- AudioCodes Limited/AudioCodes Fax/IVR Appliancev5Range: 0
- cpe:2.3:a:audiocodes:interactive_voice_response:*:*:*:*:*:*:*:*Range: <=2.6.23
Patches
Vulnerability mechanics
References
4- pierrekim.github.io/advisories/2025-audiocodes-fax-ivr.txtnvdExploitThird Party Advisory
- pierrekim.github.io/blog/2025-11-20-audiocodes-fax-ivr-8-vulnerabilities.htmlnvdExploitThird Party Advisory
- www.vulncheck.com/advisories/audiocodes-fax-ivr-appliance-world-writable-webroot-lpenvdThird Party Advisory
- www.audiocodes.com/media/g1in2u2o/0548-product-notice-end-of-service-for-audiocodes-auto-attendant-ivr-solution.pdfnvdProduct
News mentions
0No linked articles in our index yet.