{"id":"CVE-2022-50793","title":"SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php","summary":"SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-78"],"vendor":"SOUND4 Ltd.","product":"Impact/Pulse/First","affected":["Impact/Pulse/First Version 2: 1.1/2.15","impact_pulse_eco 1.16","BigVoice4 1.2","BigVoice2 1.30","Stream 1.1/2.4.29","WM2 1.11"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"total","timestamp":"2026-01-05T20:18:18.541233Z"},"exploitAvailable":true,"published":"2025-12-30","updated":"2026-10-01","sourceUpdated":"2026-10-01T19:19:11.069Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2022-50793","references":[{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5737.php","label":"Zero Science Lab Disclosure (ZSL-2022-5737)"},{"url":"https://packetstormsecurity.com/files/170264/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-services-Command-Injection.html","label":"Packet Storm Security Exploit Details"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/247917","label":"IBM X-Force Vulnerability Exchange Entry"},{"url":"https://www.sound4.com/","label":"SOUND4 Product Homepage"},{"url":"https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-authenticated-command-injection-via-www-data-handlerphp","label":"VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php"}],"tags":["cve.org","exploit-available"],"epss":0.03127,"epssPercentile":0.87407,"ingestedAt":"2026-10-01T19:58:57.578Z","slug":"CVE-2022-50793","body":"## Overview\n\nSOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute arbitrary system commands with www-data user privileges.\n\n## Affected\n\n- `Impact/Pulse/First Version 2: 1.1/2.15`\n- `impact_pulse_eco 1.16`\n- `BigVoice4 1.2`\n- `BigVoice2 1.30`\n- `Stream 1.1/2.4.29`\n- `WM2 1.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.6,"exploitation":12,"ransomware":0},"changes":[]}