PT-2025-54241 · Unknown · Sound4 Impact+3

Published

2025-12-30

·

Updated

2025-12-31

·

CVE-2022-50793

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and earlier
Description The software contains an authenticated command injection issue in the www-data-handler.php script. Attackers can inject system commands through the services POST parameter. Exploitation allows attackers to execute arbitrary system commands with www-data user privileges.
Recommendations Versions prior to 2.x should be updated. Avoid using the services parameter in the www-data-handler.php script until a fix is available.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2022-50793

Affected Products

Sound4 Eco
Sound4 First
Sound4 Impact
Sound4 Pulse