CVE-2025-32106

In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:audiocodes:mp-112_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:audiocodes:mp-112:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:audiocodes:mp-114_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:audiocodes:mp-114:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:audiocodes:mp-118_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:audiocodes:mp-118:-:*:*:*:*:*:*:*

History

09 Jun 2025, 15:13

Type Values Removed Values Added
First Time Audiocodes mp-118 Firmware
Audiocodes mp-112 Firmware
Audiocodes mp-118
Audiocodes mp-112
Audiocodes mp-114
Audiocodes mp-114 Firmware
Audiocodes
CPE cpe:2.3:o:audiocodes:mp-118_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:audiocodes:mp-112:-:*:*:*:*:*:*:*
cpe:2.3:o:audiocodes:mp-112_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:audiocodes:mp-114:-:*:*:*:*:*:*:*
cpe:2.3:h:audiocodes:mp-118:-:*:*:*:*:*:*:*
cpe:2.3:o:audiocodes:mp-114_firmware:*:*:*:*:*:*:*:*
References () https://Audiocodes.com - () https://Audiocodes.com - Product
References () https://github.com/austin2111/papers/blob/main/Software_Vulnerabilities_in_Telecommunications_Hardware.pdf - () https://github.com/austin2111/papers/blob/main/Software_Vulnerabilities_in_Telecommunications_Hardware.pdf - Exploit, Third Party Advisory

04 Jun 2025, 14:54

Type Values Removed Values Added
Summary
  • (es) En Audiocodes Mediapack MP-11x a 6.60A.369.002, una solicitud POST manipulada específicamente puede provocar que un usuario remoto no autenticado pueda ejecutar código no autorizado.

03 Jun 2025, 18:15

Type Values Removed Values Added
CWE CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

03 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-03 17:15

Updated : 2025-06-09 15:13


NVD link : CVE-2025-32106

Mitre link : CVE-2025-32106

CVE.ORG link : CVE-2025-32106


JSON object : View

Products Affected

audiocodes

  • mp-114
  • mp-118_firmware
  • mp-118
  • mp-114_firmware
  • mp-112
  • mp-112_firmware
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')