Home

Description

AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 configure the web document root at C:\\F2MAdmin\\F2E with overly permissive file system permissions. Authenticated local users have modify rights on this directory, while the associated web server process runs as NT AUTHORITY\\SYSTEM. As a result, any local user can create or alter server-side scripts within the webroot and then trigger them via HTTP requests, causing arbitrary code to execute with SYSTEM privileges.

PUBLISHED Reserved 2025-04-15 | Published 2025-11-19 | Updated 2025-11-20 | Assigner VulnCheck




HIGH: 8.5CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-276 Incorrect Default Permissions

Product status

Default status
unknown

Any version
affected

Credits

Pierre Barre finder

References

www.audiocodes.com/...ocodes-auto-attendant-ivr-solution.pdf vendor-advisory patch mitigation

pierrekim.github.io/...ocodes-fax-ivr-8-vulnerabilities.html technical-description exploit

pierrekim.github.io/advisories/2025-audiocodes-fax-ivr.txt technical-description exploit

www.vulncheck.com/...vr-appliance-world-writable-webroot-lpe third-party-advisory

cve.org (CVE-2025-34333)

nvd.nist.gov (CVE-2025-34333)

Download JSON