{"id":"CVE-2022-50791","title":"SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php","summary":"SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a …","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-78"],"vendor":"SOUND4 Ltd.","product":"Impact/Pulse/First","affected":["Impact/Pulse/First Version 2: 1.1/2.15","impact_pulse_eco 1.16","BigVoice4 1.2","BigVoice2 1.30","Stream 1.1/2.4.29","WM2 1.11"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-01-05T20:17:03.751619Z"},"exploitAvailable":true,"published":"2025-12-30","updated":"2026-10-01","sourceUpdated":"2026-10-01T19:19:09.682Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2022-50791","references":[{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5735.php","label":"Zero Science Lab Disclosure (ZSL-2022-5735)"},{"url":"https://packetstormsecurity.com/files/170262/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-ping.php-Command-Injection.html","label":"Packet Storm Security Exploit Details"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/247915","label":"IBM X-Force Vulnerability Exchange Entry"},{"url":"https://www.sound4.com/","label":"SOUND4 Product Homepage"},{"url":"https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-conditional-command-injection-via-pingphp","label":"VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php"}],"tags":["cve.org","exploit-available"],"epss":0.03759,"epssPercentile":0.8955,"ingestedAt":"2026-10-01T19:58:57.579Z","slug":"CVE-2022-50791","body":"## Overview\n\nSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a single HTTP POST request to the vulnerable ping.php script, which triggers the malicious file and then deletes it.\n\n## Affected\n\n- `Impact/Pulse/First Version 2: 1.1/2.15`\n- `impact_pulse_eco 1.16`\n- `BigVoice4 1.2`\n- `BigVoice2 1.30`\n- `Stream 1.1/2.4.29`\n- `WM2 1.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":56,"depthScoreParts":{"impact":42.9,"likelihood":0.8,"exploitation":12,"ransomware":0},"changes":[]}