CVE-2022-50794

CRITICAL WAF: High
CVSS 9.8 Published: 2025-12-30
CWE-78

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
sound4impact_firmware2.15
sound4impact_firmware1.69
sound4pulse_firmware2.15
sound4pulse_firmware1.69
sound4first_firmware2.15
sound4first_firmware1.69
sound4impact_eco_firmware1.16
sound4pulse_eco_firmware1.16
sound4big_voice4_firmware1.2
sound4big_voice2_firmware1.30

References

Back to CVE Database