PT-2025-52699 · Unknown · Sound4 Impact+3

Published

2025-12-22

·

Updated

2025-12-23

·

CVE-2023-53962

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x
Description The software contains an unauthenticated directory traversal flaw. Remote attackers can write arbitrary files by manipulating the upgfile parameter within the 'upload.cgi' script. Exploitation involves sending specially crafted multipart form-data POST requests containing directory traversal sequences, enabling file writing to unintended locations on the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2023-53962

Affected Products

Sound4 Eco
Sound4 First
Sound4 Impact
Sound4 Pulse