PT-2025-54239 · Unknown · Sound4 Impact+3

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2022-50791

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and earlier
Description The software contains a conditional command injection issue. Local authenticated users can create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by sending an HTTP POST request to the ping.php script. This script triggers the malicious file and then deletes it. The vulnerable API endpoint is /ping.php.
Recommendations Versions prior to 2.x should be updated.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-50791

Affected Products

Sound4 Eco
Sound4 First
Sound4 Impact
Sound4 Pulse