VendorsSOUND4first_firmwareall versions
Vulnerabilities

SOUND4 First Firmware

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2022-50794
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username
Published 2025-12-30 · Analyzed
9.8EPSS 0.037
CVE-2023-53963
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection
Published 2025-12-22 · Analyzed
9.8EPSS 0.034
CVE-2022-50796
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi
Published 2025-12-30 · Modified
9.8EPSS 0.016
CVE-2023-53964
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability
Published 2025-12-22 · Modified
9.8EPSS 0.010
CVE-2022-50694
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter
Published 2025-12-30 · Modified
9.8EPSS 0.009
CVE-2023-53955
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References
Published 2025-12-22 · Analyzed
9.8EPSS 0.009
CVE-2023-53960
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x SQL Injection via Authentication Bypass
Published 2025-12-22 · Modified
9.8EPSS 0.007
CVE-2022-50696
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass
Published 2025-12-30 · Modified
9.8EPSS 0.006
CVE-2022-50793
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php
Published 2025-12-30 · Analyzed
8.8EPSS 0.032
CVE-2023-53962
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write
Published 2025-12-22 · Modified
8.8EPSS 0.012
CVE-2022-50792
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability
Published 2025-12-30 · Modified
8.7EPSS 0.015
CVE-2022-50695
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands
Published 2025-12-30 · Modified
8.7EPSS 0.008
CVE-2023-53965
SOUND4 Server Service 4.1.102 Local Privilege Escalation via Unquoted Service Path
Published 2025-12-22 · Analyzed
8.6EPSS 0.002
CVE-2022-50789
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.php
Published 2025-12-30 · Modified
8.5EPSS 0.043
CVE-2022-50795
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php
Published 2025-12-30 · Modified
8.5EPSS 0.042
CVE-2022-50791
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php
Published 2025-12-30 · Modified
8.5EPSS 0.038
CVE-2022-50788
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory
Published 2025-12-30 · Analyzed
7.5EPSS 0.008
CVE-2022-50790
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure
Published 2025-12-30 · Modified
7.5EPSS 0.008
CVE-2022-50692
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability
Published 2025-12-30 · Analyzed
7.5EPSS 0.006
CVE-2025-63220
The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.
Published 2025-11-19 · Analyzed
7.2EPSS 0.005
CVE-2022-50787
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting
Published 2025-12-30 · Analyzed
7.2EPSS 0.004
CVE-2023-53961
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery
Published 2025-12-22 · Modified
5.1EPSS 0.002