« Back to list

Sound4

Sound4 Stream Extension: vulnerabilities and CVEs

Sound4 Stream Extension has 20 published vulnerabilities, 20 of them in the last 12 months. 6 are rated critical and 0 are listed by CISA as actively exploited.

CVEs20
Last 12 months20
Critical6
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-50796Critical (9.3)1.6%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write…
CVE-2022-50795High (8.5)4.2%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute…
CVE-2022-50794Critical (9.3)3.7%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary…
CVE-2022-50793High (8.7)3.1%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter.…
CVE-2022-50792High (8.7)1.6%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by…
CVE-2022-50791High (8.5)3.8%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute…
CVE-2022-50790Medium (6.9)0.79%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit…
CVE-2022-50789High (8.5)4.2%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can…
CVE-2022-50788Medium (6.9)0.83%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve…
CVE-2022-50787Medium (5.3)0.44%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the…
CVE-2022-50696Critical (9.3)0.60%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to…
CVE-2022-50695High (8.7)0.80%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php,…
CVE-2022-50694High (8.8)0.89%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code…
CVE-2022-50692Medium (6.9)0.58%—Dec 30, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to…
CVE-2023-53964High (8.8)0.98%—Dec 22, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request…
CVE-2023-53963Critical (9.3)3.4%—Dec 22, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit…
CVE-2023-53962High (8.8)1.2%—Dec 22, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit…
CVE-2023-53961Medium (5.1)0.19%—Dec 22, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit…
CVE-2023-53960Critical (9.3)0.74%—Dec 22, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL…
CVE-2023-53955Critical (9.3)0.85%—Dec 22, 2025
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by…

Other products by Sound4