VendorsSOUND4pulse-eco_aes67all versions
Vulnerabilities

SOUND4 Pulse-eco aes67

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-57431
The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.
Published 2025-09-22 · Analyzed
8.8EPSS 0.003