CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “audiocodes”

33 vulnerabilities found for “audiocodes”

Page 1 of 2

CVE-2025-32106
CRITICAL9.8

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

audiocodes / mp-112_firmware+2
Network
Published Jun 3, 2025
Page 1 of 2
CVE-2024-52881
HIGH7.5

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to the use of a hard-coded key, an attacker is able to decrypt sensitive data such as passwords extracted from the topology file.

audiocodes / one_voice_operations_center
Network
Published Feb 7, 2025
CVE-2024-52882
MEDIUM6.1

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to improper neutralization of input via the devices API, an attacker can inject malicious JavaScript code (XSS) to attack logged-in administrator sessions.

audiocodes / one_voice_operations_center
Network
Published Feb 7, 2025
CVE-2024-52883
HIGH7.5

An issue was discovered in AudioCodes One Voice Operations Center (OVOC) before 8.4.582. Due to a path traversal vulnerability, sensitive data can be read without any authentication.

audiocodes / one_voice_operations_center
Network
Published Feb 7, 2025
CVE-2023-22955
HIGH7.8

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. The validation of firmware images only consists of simple checksum checks for different firmware components. Thus, by knowing how to calculate and where to store the required checksums for the flasher tool, an attacker is able to store malicious firmware.

audiocodes / 445hd_firmware+2
Local
Published Aug 11, 2023
CVE-2023-22956
HIGH7.5

An issue was discovered on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of a hard-coded cryptographic key, an attacker is able to decrypt encrypted configuration files and retrieve sensitive information.

audiocodes / c470hd_firmware+5
Network
Published Aug 11, 2023
CVE-2023-22957
HIGH7.5

An issue was discovered in libac_des3.so on AudioCodes VoIP desk phones through 3.4.4.1000. Due to the use of hard-coded cryptographic key, an attacker with access to backup or configuration files is able to decrypt encrypted values and retrieve sensitive information, e.g., the device root password.

audiocodes / c470hd_firmware+5
Network
Published Aug 11, 2023
CVE-2022-24632
MEDIUM5.3

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is directory traversal during file download via the BrowseFiles.php view parameter.

audiocodes / device_manager_express
Network
Published May 29, 2023
CVE-2022-24631
MEDIUM5.4

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is stored XSS via the ajaxTenants.php desc parameter.

audiocodes / device_manager_express
Network
Published May 29, 2023
CVE-2022-24628
HIGH7.2

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is authenticated SQL injection in the id parameter of IPPhoneFirmwareEdit.php.

audiocodes / device_manager_express
Network
Published May 29, 2023
CVE-2022-24630
HIGH7.2

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. BrowseFiles.php allows a ?cmd=ssh POST request with an ssh_command field that is executed.

audiocodes / device_manager_express
Network
Published May 29, 2023
CVE-2022-24629
CRITICAL9.8

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. Remote code execution can be achieved via directory traversal in the dir parameter of the file upload functionality of BrowseFiles.php. An attacker can upload a .php file to WebAdmin/admin/AudioCodes_files/ajax/.

audiocodes / device_manager_express
Network
Published May 29, 2023
CVE-2022-24627
CRITICAL9.8

An issue was discovered in AudioCodes Device Manager Express through 7.8.20002.47752. It is an unauthenticated SQL injection in the p parameter of the process_login.php login form.

audiocodes / device_manager_express
Network
Published May 29, 2023
CVE-2019-9229
HIGH8.8

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.251. An internal interface exposed to the link-local address 169.254.254.253 allows attackers in the local network to access multiple quagga VTYs. Attackers can authenticate with the default 1234 password that cannot be changed, and can execute malicious and unauthorized actions.

audiocodes / median_500l-msbr_firmware+3
Adjacent
Published Jul 20, 2019
CVE-2019-9228
HIGH7.5

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A at least to 7.20A.252.062. The (1) management SSH and (2) management TELNET features allow remote attackers to cause a denial of service (connection slot exhaustion) via 5 unauthenticated connection attempts, because the maximum number of unauthenticated clients that can be configured is 5. NOTE: the vendor's position is that this is a "design choice.

audiocodes / median_500l-msbr_firmware+3
Network
Published Jul 19, 2019
CVE-2019-9231
HIGH8.8

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.

audiocodes / mediant_500l-msbr_firmware+3
Network
Published Jul 18, 2019
CVE-2019-9230
MEDIUM6.1

An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions F7.20A to F7.20A.253. A cross-site scripting (XSS) vulnerability in the search function of the management web interface allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

audiocodes / mediant_500l-msbr_firmware+3
Network
Published Jul 18, 2019
CVE-2018-16219
HIGH8.8

A missing password verification in the web interface in AudioCodes 405HD VoIP phone with firmware 2.2.12 allows an remote attacker (in the same network as the device) to change the admin password without authentication via a POST request.

audiocodes / 405hd_firmware
Adjacent
Published Apr 25, 2019
CVE-2018-16216
HIGH8.0

A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP phone allows an authenticated remote attacker in the same network as the device to trigger OS commands (like starting telnetd or opening a reverse shell) via a POST request to the web server. In combination with another attack (unauthenticated password change), the attacker can circumvent the authentication requirement.

audiocodes / 405hd_firmware
Adjacent
Published Apr 25, 2019
CVE-2018-18567
MEDIUM5.9

AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.

audiocodes / 440hd_firmware+1
Network
Published Oct 24, 2018