SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi
Published Dec 30, 2025
9.3
CRITICALCVSS 4.0
EPSS 1.57%
Description
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.
Affected products
-
- Version 1.11StatusaffectedConstraints-
- Version
-
- Version 1.30StatusaffectedConstraints-
- Version
-
- Version 1.2StatusaffectedConstraints-
- Version
-
- Version 1.16StatusaffectedConstraints-
- Version
-
- Version Version 2: 1.1/2.15StatusaffectedConstraints-
- Version
-
- Version 1.1/2.4.29StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Kantar Media | WM2 | n/a |
| ||||||
| SOUND4 Ltd. | BigVoice2 | n/a |
| ||||||
| SOUND4 Ltd. | BigVoice4 | n/a |
| ||||||
| SOUND4 Ltd. | Impact/Pulse Eco | n/a |
| ||||||
| SOUND4 Ltd. | Impact/Pulse/First | n/a |
| ||||||
| SOUND4 Ltd. | Stream | n/a |
|
Configuration 1
- 2.15
Configuration 2
- 1.69
Configuration 3
- 2.15
Configuration 4
- 1.69
Configuration 5
- 2.15
Configuration 6
- 1.69
Configuration 7
- 1.16
Running on/with
- n/a
Configuration 8
- 1.16
Configuration 9
- 1.2
Running on/with
- n/a
Configuration 10
- 1.30
Running on/with
- n/a
Configuration 11
- 1.11
Configuration 12
- 2.4.29
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55930 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/247951 vdb-entryThird Party Advisory
- https://packetstormsecurity.com/files/170268/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-upload.cgi-Code-Execution.html exploitThird Party AdvisoryVDB Entry
- https://www.sound4.com/ product
- https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-remote-code-execution-via-uploadcgi third-party-advisoryThird Party Advisory
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5741.php third-party-advisoryExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-55930 | Advisory | |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/247951 | vdb-entryThird Party Advisory | |
| https://packetstormsecurity.com/files/170268/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-upload.cgi-Code-Execution.html | exploitThird Party AdvisoryVDB Entry | |
| https://www.sound4.com/ | product | |
| https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-remote-code-execution-via-uploadcgi | third-party-advisoryThird Party Advisory | |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5741.php | third-party-advisoryExploitThird Party Advisory |
Change history (0)
No recorded changes yet.