CVE-2023-53963
9.8
CRITICAL · CVSS 3.1 · EPSS 3.4% (pctl 89)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 3.4% — more likely to be exploited than 89% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2025-12-22 |
| Last modified | 2026-06-17 |
Affected (17)
| Vendor | Product |
|---|---|
| sound4 | big voice2 |
| sound4 | big voice2 firmware |
| sound4 | big voice4 |
| sound4 | big voice4 firmware |
| sound4 | first |
| sound4 | first firmware |
| sound4 | impact |
| sound4 | impact eco |
| sound4 | impact eco firmware |
| sound4 | impact firmware |
| sound4 | pulse |
| sound4 | pulse eco |
| sound4 | pulse eco firmware |
| sound4 | pulse firmware |
| sound4 | stream extension |
| sound4 | wm2 |
| sound4 | wm2 firmware |
References
- https://web.archive.org/web/20221207074555/https://www.sound4.com/
- https://www.exploit-db.com/exploits/51173
- https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-remote-command-injection
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5738.php
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5738.php
→ the Explorer · watch your stack · NVD