Sound4
Sound4 First Firmware: vulnerabilidades y CVE
Sound4 First Firmware tiene 22 vulnerabilidades publicadas, 22 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE22
Últimos 12 meses22
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-50796 | Crítica (9.3) | 1.6% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write… |
| CVE-2022-50795 | Alta (8.5) | 4.2% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute… |
| CVE-2022-50794 | Crítica (9.3) | 3.7% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary… |
| CVE-2022-50793 | Alta (8.7) | 3.1% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter.… |
| CVE-2022-50792 | Alta (8.7) | 1.6% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by… |
| CVE-2022-50791 | Alta (8.5) | 3.8% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute… |
| CVE-2022-50790 | Media (6.9) | 0.79% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit… |
| CVE-2022-50789 | Alta (8.5) | 4.2% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can… |
| CVE-2022-50788 | Media (6.9) | 0.83% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve… |
| CVE-2022-50787 | Media (5.3) | 0.44% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the… |
| CVE-2022-50696 | Crítica (9.3) | 0.60% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to… |
| CVE-2022-50695 | Alta (8.7) | 0.80% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php,… |
| CVE-2022-50694 | Alta (8.8) | 0.89% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code… |
| CVE-2022-50692 | Media (6.9) | 0.58% | — | 30 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to… |
| CVE-2023-53965 | Alta (8.6) | 0.24% | — | 22 dic 2025 | SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary… |
| CVE-2023-53964 | Alta (8.8) | 0.98% | — | 22 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request… |
| CVE-2023-53963 | Crítica (9.3) | 3.4% | — | 22 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit… |
| CVE-2023-53962 | Alta (8.8) | 1.2% | — | 22 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit… |
| CVE-2023-53961 | Media (5.1) | 0.19% | — | 22 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit… |
| CVE-2023-53960 | Crítica (9.3) | 0.74% | — | 22 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL… |
| CVE-2023-53955 | Crítica (9.3) | 0.85% | — | 22 dic 2025 | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by… |
| CVE-2025-63220 | Alta (7.2) | 0.46% | — | 19 nov 2025 | The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an… |