Skip to main content

Vendor/product archive

sound4 / first CVEs

Beta · best-effort

21 CVEs tagged to sound4 / first6 Critical, 10 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2022-50796

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can ex…

CVSS 9.3 · Critical

CVE-2022-50795

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. U…

CVSS 8.5 · High

CVE-2022-50794

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and logi…

CVSS 9.3 · Critical

CVE-2022-50793

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands th…

CVSS 8.7 · High

CVE-2022-50792

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attack…

CVSS 8.7 · High

CVE-2022-50791

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. U…

CVSS 8.5 · High

CVE-2022-50790

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay…

CVSS 6.9 · Medium

CVE-2022-50789

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid…

CVSS 8.5 · High

CVE-2022-50788

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly br…

CVSS 6.9 · Medium

CVE-2022-50787

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject maliciou…

CVSS 5.3 · Medium

CVE-2022-50696

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers…

CVSS 9.3 · Critical

CVE-2022-50695

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command s…

CVSS 8.7 · High

CVE-2022-50694

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Att…

CVSS 8.8 · High

CVE-2022-50692

Published Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can…

CVSS 6.9 · Medium

CVE-2023-53964

Published Dec 22, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configura…

CVSS 8.8 · High

CVE-2023-53963

Published Dec 22, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'pas…

CVSS 9.3 · Critical

CVE-2023-53962

Published Dec 22, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parame…

CVSS 8.8 · High

CVE-2023-53961

Published Dec 22, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can…

CVSS 5.1 · Medium

CVE-2023-53960

Published Dec 22, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials…

CVSS 9.3 · Critical

CVE-2023-53955

Published Dec 22, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Att…

CVSS 9.3 · Critical

CVE-2025-63220

Published Nov 19, 2025

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the in…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-21 of 21 CVEsPage 1 of 1