peter bassill · operator
$ cve CVE-2022-50794 JSON

CVE-2022-50794

9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.66% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2025-12-30
Last modified2026-06-17

Affected (17)

VendorProduct
sound4big voice2
sound4big voice2 firmware
sound4big voice4
sound4big voice4 firmware
sound4first
sound4first firmware
sound4impact
sound4impact eco
sound4impact eco firmware
sound4impact firmware
sound4pulse
sound4pulse eco
sound4pulse eco firmware
sound4pulse firmware
sound4stream extension
sound4wm2
sound4wm2 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD