CVE-2022-50794
9.8
CRITICAL · CVSS 3.1 · EPSS 3.7% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.66% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-12-30 |
| Last modified | 2026-06-17 |
Affected (17)
| Vendor | Product |
|---|---|
| sound4 | big voice2 |
| sound4 | big voice2 firmware |
| sound4 | big voice4 |
| sound4 | big voice4 firmware |
| sound4 | first |
| sound4 | first firmware |
| sound4 | impact |
| sound4 | impact eco |
| sound4 | impact eco firmware |
| sound4 | impact firmware |
| sound4 | pulse |
| sound4 | pulse eco |
| sound4 | pulse eco firmware |
| sound4 | pulse firmware |
| sound4 | stream extension |
| sound4 | wm2 |
| sound4 | wm2 firmware |
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/247914
- https://packetstormsecurity.com/files/170266/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-username-Command-Injection.html
- https://www.sound4.com/
- https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-command-injection-via-username
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5739.php
→ the Explorer · watch your stack · NVD