SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability
Published Dec 30, 2025
8.7
HIGHCVSS 4.0
EPSS 1.57%
Description
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected device.
Affected products
-
Affected
- 1.11
-
Affected
- 1.30
-
Affected
- 1.2
-
Affected
- 1.16
-
Affected
- Version 2: 1.1/2.15
-
Affected
- 1.1/2.4.29
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Kantar Media | WM2 | unknown | Affected
|
| SOUND4 Ltd. | BigVoice2 | unknown | Affected
|
| SOUND4 Ltd. | BigVoice4 | unknown | Affected
|
| SOUND4 Ltd. | Impact/Pulse Eco | unknown | Affected
|
| SOUND4 Ltd. | Impact/Pulse/First | unknown | Affected
|
| SOUND4 Ltd. | Stream | unknown | Affected
|
Configuration 1
- 2.15
Configuration 2
- 1.69
Configuration 3
- 2.15
Configuration 4
- 1.69
Configuration 5
- 2.15
Configuration 6
- 1.69
Configuration 7
- 1.16
Running on/with
- n/a
Configuration 8
- 1.16
Configuration 9
- 1.2
Running on/with
- n/a
Configuration 10
- 1.30
Running on/with
- n/a
Configuration 11
- 1.11
Configuration 12
- 2.4.29
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55934 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/247916 vdb-entryThird Party Advisory
- https://packetstormsecurity.com/files/170263/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Unauthenticated-File-Disclosure.html exploitThird Party AdvisoryVDB Entry
- https://www.sound4.com/ product
- https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-file-disclosure-vulnerability third-party-advisoryThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5736.php third-party-advisoryExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55934 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/247916 | vdb-entryThird Party Advisory | |
| https://packetstormsecurity.com/files/170263/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Unauthenticated-File-Disclosure.html | exploitThird Party AdvisoryVDB Entry | |
| https://www.sound4.com/ | product | |
| https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-file-disclosure-vulnerability | third-party-advisoryThird Party Advisory | |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5736.php | third-party-advisoryExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data