PT-2025-52700 · Unknown · Sound4 Impact+3
Published
2025-12-22
·
Updated
2025-12-23
·
CVE-2023-53963
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x
Description
The software contains an unauthenticated OS command injection issue that allows remote attackers to execute arbitrary shell commands. This is possible through the 'password' parameter in the login.php and index.php scripts. Attackers can inject shell commands via the
password POST parameter, enabling them to execute commands with web server privileges.Recommendations
Versions prior to 2.x should be updated. As a temporary workaround, restrict access to the login.php and index.php scripts to minimize the risk of exploitation. Avoid using the
password parameter in the affected API endpoints until the issue is resolved.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sound4 Eco
Sound4 First
Sound4 Impact
Sound4 Pulse