PT-2025-54237 · Unknown · Sound4 Impact+3

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2022-50789

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and earlier
Description The software contains a command injection issue. Local authenticated users can create malicious files in the /tmp directory with a '.dns.pid' extension. An unauthenticated attacker can execute malicious commands by sending an HTTP POST request to the dns.php script. This script triggers command execution and then deletes the file. The API endpoint involved is /dns.php.
Recommendations Versions prior to 2.x should be updated.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-50789

Affected Products

Sound4 Eco
Sound4 First
Sound4 Impact
Sound4 Pulse