peter bassill · operator
$ cve CVE-2023-53963 JSON

CVE-2023-53963

9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.4% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploitnone known
Published2025-12-22
Last modified2026-06-17

Affected (17)

VendorProduct
sound4big voice2
sound4big voice2 firmware
sound4big voice4
sound4big voice4 firmware
sound4first
sound4first firmware
sound4impact
sound4impact eco
sound4impact eco firmware
sound4impact firmware
sound4pulse
sound4pulse eco
sound4pulse eco firmware
sound4pulse firmware
sound4stream extension
sound4wm2
sound4wm2 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD