Unauthenticated Command Injection in SOUND4 IMPACT/FIRST/PULSE/Eco
CVE-2022-50794
Key Information:
- Vendor
Sound4 Ltd.
- Vendor
- CVE Published:
- 30 December 2025
Badges
What is CVE-2022-50794?
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and earlier are susceptible to an unauthenticated command injection vulnerability through the 'username' parameter. This weakness allows attackers to exploit the index.php and login.php scripts by injecting arbitrary shell commands via HTTP POST requests. Successful exploitation enables malicious actors to execute system commands, potentially compromising the integrity and security of the affected systems.
Affected Version(s)
BigVoice2 1.30
BigVoice4 1.2
Impact/Pulse Eco 1.16
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
