PT-2025-52700 · Unknown · Sound4 Impact+3

Published

2025-12-22

·

Updated

2025-12-23

·

CVE-2023-53963

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x
Description The software contains an unauthenticated OS command injection issue that allows remote attackers to execute arbitrary shell commands. This is possible through the 'password' parameter in the login.php and index.php scripts. Attackers can inject shell commands via the password POST parameter, enabling them to execute commands with web server privileges.
Recommendations Versions prior to 2.x should be updated. As a temporary workaround, restrict access to the login.php and index.php scripts to minimize the risk of exploitation. Avoid using the password parameter in the affected API endpoints until the issue is resolved.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2023-53963

Affected Products

Sound4 Eco
Sound4 First
Sound4 Impact
Sound4 Pulse