AudioCodes develops a focused line of voice-communications and unified-messaging appliances—including fax servers, interactive voice response systems, and session border controllers such as the 405HD—that sit at the edge of enterprise telephony infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a tendency to acquire public exploit code, though the exposure remains concentrated in the specialized communications appliance segment. The recurring weakness classes—cross-site scripting, OS command injection, path traversal, unrestricted file upload, and hard-coded credentials—reflect the web-management interfaces and embedded configuration mechanisms common to appliance firmware. Defenders should prioritize patching for internet-reachable instances, as these devices often serve as ingress points to voice and messaging infrastructure; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Audiocodes over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10093HIGH AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution. | Mar 21, 2019 | 8.8 | 81 | NO | YES |
CVE-2022-24627CRITICAL An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form. | May 29, 2023 | 9.8 | 63 | NO | YES |
CVE-2022-24629CRITICAL An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file | May 29, 2023 | 9.8 | 61 | NO | YES |
CVE-2022-24630HIGH An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed. | May 29, 2023 | 7.2 | 44 | NO | YES |
CVE-2022-24632MEDIUM An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter. | May 29, 2023 | 5.3 | 40 | NO | YES |
CVE-2022-24631MEDIUM An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter. | May 29, 2023 | 5.4 | 39 | NO | NO |
CVE-2025-34329CRITICAL AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFil | Nov 19, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-34328CRITICAL AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script | Nov 19, 2025 | 9.8 | 32 | NO | NO |
CVE-2025-34335HIGH AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workfl | Nov 19, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-34334HIGH AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality imple | Nov 19, 2025 | 8.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Audiocodes.
Media articles that mention a CVE ID that affects a product developed by Audiocodes — matched by CVE ID, not by vendor name.