PT-2025-47408 · Unknown · Sound4 Impact

Published

2025-11-18

·

Updated

2025-11-19

·

CVE-2025-63215

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sound4 IMPACT (affected versions not specified)
Description The Sound4 IMPACT web-based management interface contains a flaw that allows for Remote Code Execution (RCE). This occurs because the system does not properly validate the integrity of the manual.sh script during a firmware update. An attacker can exploit this by modifying the script to include arbitrary commands and then repackaging the firmware, leading to potential system compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-63215

Affected Products

Sound4 Impact