CVE-2022-50791

HIGH WAF: High
CVSS 7.8 Published: 2025-12-30
CWE-78

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the vulnerable ping.php script, which triggers the malicious file and then deletes it.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
sound4impact_firmware2.15
sound4impact_firmware1.69
sound4pulse_firmware2.15
sound4pulse_firmware1.69
sound4first_firmware2.15
sound4first_firmware1.69
sound4impact_eco_firmware1.16
sound4pulse_eco_firmware1.16
sound4big_voice4_firmware1.2
sound4big_voice2_firmware1.30

References

Back to CVE Database