audiocodes records
33 published records for vendor audiocodes.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-798 Use of Hard-coded Credentials3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-434 Unrestricted Upload of File with Dangerous Type3
- CWE-276 Incorrect Default Permissions2
The weakness classes this vendor ships most often: where to look.
CWEAll records
33 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
55Plan | CVE-2018-10093Proof of concept | AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.audiocodes · 420hd ip phone firmware · CWE-862 | High8.8 | — | 68.2% | Mar 21, 2019 |
50Plan | CVE-2022-24629Proof of concept | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.audiocodes · device manager express · CWE-22 | Critical9.8 | — | 37.2% | May 29, 2023 |
47Plan | CVE-2022-24627Proof of concept | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.audiocodes · device manager express · CWE-89 | Critical9.8 | — | 26.4% | May 29, 2023 |
39Monitor | CVE-2025-32106No exploit | In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability audiocodes · mp-112 firmware · CWE-94 | Critical9.8 | — | 1.0% | Jun 3, 2025 |
37Monitor | CVE-2018-5757No exploit | An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106.audiocodes · 420hd ip phone firmware · CWE-78 | High8.8 | — | 7.6% | Apr 1, 2019 |
37Monitor | CVE-2025-34329No exploit | AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated Backup Upload RCE via ajaxBackupUploadFile.phpaudiocodes · fax server · CWE-434 | Critical9.3 | — | 1.1% | Nov 19, 2025 |
37Monitor | CVE-2025-34328No exploit | AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Upload RCE via ajaxScript.phpaudiocodes · fax server · CWE-434 | Critical9.3 | — | 0.7% | Nov 19, 2025 |
35Monitor | CVE-2022-24630Proof of concept | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.audiocodes · device manager express · CWE-77 | High7.2 | — | 23.9% | May 29, 2023 |
35Monitor | CVE-2025-34334No exploit | AudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via TestFax.php & LPEaudiocodes · fax server · CWE-78 | High8.7 | — | 3.4% | Nov 19, 2025 |
35Monitor | CVE-2025-34335No exploit | AudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via ActivateLicense.phpaudiocodes · fax server · CWE-78 | High8.7 | — | 2.8% | Nov 19, 2025 |
35Monitor | CVE-2018-16219No exploit | A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the saudiocodes · 405hd firmware · CWE-287 | High8.8 | — | 1.2% | Apr 25, 2019 |
35Monitor | CVE-2019-9231No exploit | An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.audiocodes · mediant 500l-msbr firmware · CWE-352 | High8.8 | — | 0.7% | Jul 18, 2019 |
35Monitor | CVE-2019-9229No exploit | An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.audiocodes · median 500l-msbr firmware · CWE-798 | High8.8 | — | 0.6% | Jul 19, 2019 |
34Monitor | CVE-2025-34331No exploit | AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Read via download.phpaudiocodes · fax server · CWE-306 | High8.7 | — | 0.5% | Nov 19, 2025 |
34Monitor | CVE-2025-34332No exploit | AudioCodes Fax/IVR Appliance <= 2.6.23 Insecure Service Control Scripts LPEaudiocodes · fax server · CWE-276 | High8.5 | — | 0.2% | Nov 19, 2025 |
34Monitor | CVE-2025-34333No exploit | AudioCodes Fax/IVR Appliance <= 2.6.23 World-Writable Webroot LPEaudiocodes · fax server · CWE-276 | High8.5 | — | 0.2% | Nov 19, 2025 |
33Monitor | CVE-2022-24631No exploit | An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.audiocodes · device manager express · CWE-79 | Medium5.4 | — | 41.4% | May 29, 2023 |
33Monitor | CVE-2018-16216No exploit | A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.audiocodes · 405hd firmware · CWE-78 | High8.0 | — | 4.1% | Apr 25, 2019 |
31Monitor | CVE-2019-9228No exploit | An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least taudiocodes · median 500l-msbr firmware | High7.5 | — | 1.8% | Jul 19, 2019 |
31Monitor | CVE-2023-22955No exploit | An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000.audiocodes · 445hd firmware · CWE-345 | High7.8 | — | 0.3% | Aug 11, 2023 |
30Monitor | CVE-2023-22956No exploit | An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000.audiocodes · c470hd firmware · CWE-798 | High7.5 | — | 1.4% | Aug 11, 2023 |
30Monitor | CVE-2023-22957No exploit | An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000.audiocodes · c470hd firmware · CWE-798 | High7.5 | — | 1.4% | Aug 11, 2023 |
30Monitor | CVE-2024-52883No exploit | An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582.audiocodes · one voice operations center · CWE-22 | High7.5 | — | 0.7% | Feb 7, 2025 |
30Monitor | CVE-2024-52881No exploit | An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582.audiocodes · one voice operations center · CWE-321 | High7.5 | — | 0.4% | Feb 7, 2025 |
30Monitor | CVE-2024-52884No exploit | An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841.audiocodes · mediant session border controller · CWE-327 | High7.5 | — | 0.2% | Feb 7, 2025 |
- CVE-2018-1009355Plan
AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.
HighCVSS 8.8Proof of conceptEPSS 68%audiocodes · 420hd ip phone firmwareMar 21, 2019
- CVE-2022-2462950Plan
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.
CriticalCVSS 9.8Proof of conceptEPSS 37%audiocodes · device manager expressMay 29, 2023
- CVE-2022-2462747Plan
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.
CriticalCVSS 9.8Proof of conceptEPSS 26%audiocodes · device manager expressMay 29, 2023
- CVE-2025-3210639Monitor
In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability
CriticalCVSS 9.8No exploitEPSS 1%audiocodes · mp-112 firmwareJun 3, 2025
- CVE-2018-575737Monitor
An issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106.
HighCVSS 8.8No exploitEPSS 8%audiocodes · 420hd ip phone firmwareApr 1, 2019
- CVE-2025-3432937Monitor
AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated Backup Upload RCE via ajaxBackupUploadFile.php
CriticalCVSS 9.3No exploitEPSS 1%audiocodes · fax serverNov 19, 2025
- CVE-2025-3432837Monitor
AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Upload RCE via ajaxScript.php
CriticalCVSS 9.3No exploitEPSS 1%audiocodes · fax serverNov 19, 2025
- CVE-2022-2463035Monitor
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.
HighCVSS 7.2Proof of conceptEPSS 24%audiocodes · device manager expressMay 29, 2023
- CVE-2025-3433435Monitor
AudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via TestFax.php & LPE
HighCVSS 8.7No exploitEPSS 3%audiocodes · fax serverNov 19, 2025
- CVE-2025-3433535Monitor
AudioCodes Fax/IVR Appliance <= 2.6.23 Authenticated Command Injection via ActivateLicense.php
HighCVSS 8.7No exploitEPSS 3%audiocodes · fax serverNov 19, 2025
- CVE-2018-1621935Monitor
A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the s
HighCVSS 8.8No exploitEPSS 1%audiocodes · 405hd firmwareApr 25, 2019
- CVE-2019-923135Monitor
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.
HighCVSS 8.8No exploitEPSS 1%audiocodes · mediant 500l-msbr firmwareJul 18, 2019
- CVE-2019-922935Monitor
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.
HighCVSS 8.8No exploitEPSS 1%audiocodes · median 500l-msbr firmwareJul 19, 2019
- CVE-2025-3433134Monitor
AudioCodes Fax/IVR Appliance <= 2.6.23 Unauthenticated File Read via download.php
HighCVSS 8.7No exploitEPSS 1%audiocodes · fax serverNov 19, 2025
- CVE-2025-3433234Monitor
AudioCodes Fax/IVR Appliance <= 2.6.23 Insecure Service Control Scripts LPE
HighCVSS 8.5No exploitEPSS 0%audiocodes · fax serverNov 19, 2025
- CVE-2025-3433334Monitor
AudioCodes Fax/IVR Appliance <= 2.6.23 World-Writable Webroot LPE
HighCVSS 8.5No exploitEPSS 0%audiocodes · fax serverNov 19, 2025
- CVE-2022-2463133Monitor
An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752.
MediumCVSS 5.4No exploitEPSS 41%audiocodes · device manager expressMay 29, 2023
- CVE-2018-1621633Monitor
A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.
HighCVSS 8.0No exploitEPSS 4%audiocodes · 405hd firmwareApr 25, 2019
- CVE-2019-922831Monitor
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least t
HighCVSS 7.5No exploitEPSS 2%audiocodes · median 500l-msbr firmwareJul 19, 2019
- CVE-2023-2295531Monitor
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000.
HighCVSS 7.8No exploitEPSS 0%audiocodes · 445hd firmwareAug 11, 2023
- CVE-2023-2295630Monitor
An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000.
HighCVSS 7.5No exploitEPSS 1%audiocodes · c470hd firmwareAug 11, 2023
- CVE-2023-2295730Monitor
An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000.
HighCVSS 7.5No exploitEPSS 1%audiocodes · c470hd firmwareAug 11, 2023
- CVE-2024-5288330Monitor
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582.
HighCVSS 7.5No exploitEPSS 1%audiocodes · one voice operations centerFeb 7, 2025
- CVE-2024-5288130Monitor
An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582.
HighCVSS 7.5No exploitEPSS 0%audiocodes · one voice operations centerFeb 7, 2025
- CVE-2024-5288430Monitor
An issue was discovered in AudioCodes Mediant Session Border Controller (SBC) before 7.40A.501.841.
HighCVSS 7.5No exploitEPSS 0%audiocodes · mediant session border controllerFeb 7, 2025