Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Audiocodes

First CVE: Oct 24, 2018Active for: 8 yearsTotal CVEs: 33
57.5
VTI Score
TOP TARGET

AudioCodes develops a focused line of voice-communications and unified-messaging appliances—including fax servers, interactive voice response systems, and session border controllers such as the 405HD—that sit at the edge of enterprise telephony infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a tendency to acquire public exploit code, though the exposure remains concentrated in the specialized communications appliance segment. The recurring weakness classes—cross-site scripting, OS command injection, path traversal, unrestricted file upload, and hard-coded credentials—reflect the web-management interfaces and embedded configuration mechanisms common to appliance firmware. Defenders should prioritize patching for internet-reachable instances, as these devices often serve as ingress points to voice and messaging infrastructure; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Audiocodes over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 24, 2018
7 years ago
Most Recent CVE
Nov 19, 2025
247 days ago

Products(45 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-10093HIGH
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
Mar 21, 20198.881NOYES
CVE-2022-24627CRITICAL
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.
May 29, 20239.863NOYES
CVE-2022-24629CRITICAL
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file
May 29, 20239.861NOYES
CVE-2022-24630HIGH
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.
May 29, 20237.244NOYES
CVE-2022-24632MEDIUM
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.
May 29, 20235.340NOYES
CVE-2022-24631MEDIUM
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.
May 29, 20235.439NONO
CVE-2025-34329CRITICAL
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an unauthenticated backup upload endpoint at AudioCodes_files/ajaxBackupUploadFil
Nov 19, 20259.832NONO
CVE-2025-34328CRITICAL
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration component (F2MAdmin) that exposes an unauthenticated script
Nov 19, 20259.832NONO
CVE-2025-34335HIGH
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 expose an authenticated command injection vulnerability in the license activation workfl
Nov 19, 20258.830NONO
CVE-2025-34334HIGH
AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 are vulnerable to an authenticated command injection in the fax test functionality imple
Nov 19, 20258.830NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
24%
61%
15%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local3 (9.1%)
Network27 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network3 (9.1%)
Attack Complexity
Low32 (97.0%)
High1 (3.0%)
Unknown0 (0.0%)
User Interaction
None27 (81.8%)
Unknown0 (0.0%)
Required6 (18.2%)
Privileges Required
Low9 (27.3%)
High3 (9.1%)
None21 (63.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
6.1% of CVEs· 96th percentile
ExploitDB
5 CVEs
15.2% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Audiocodes.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Audiocodes — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Audiocodes's Products

View all 2 CNAs →

Top CWEs