VYPR

Auto-Attendant IVR

by AudioCodes

CVEs (4)

  • CVE-2025-34328CriNov 19, 2025
    risk 0.64cvss 9.8epss 0.01

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script-management endpoint at AudioCodes_files/utils/IVR/diagram/ajaxScript.php. The saveScript action…

  • CVE-2025-34335HigNov 19, 2025
    risk 0.57cvss 8.8epss 0.03

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workflow handled by AudioCodes_files/ActivateLicense.php. When a license file is uploaded, the…

  • CVE-2025-34333HigNov 19, 2025
    risk 0.51cvss 7.8epss 0.00

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated…

  • CVE-2025-34332HigNov 19, 2025
    risk 0.51cvss 7.8epss 0.00

    AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component that controls back-end Windows services using helper batch scripts located under C:\\F2MAdmin\\F2E\\AudioCodes_files\\utils\\Services. When certain…