{"id":"CVE-2023-53964","title":"SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability","summary":"SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint wi…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cvssSource":"cna","cwe":["CWE-306"],"vendor":"SOUND4 Ltd.","product":"Impact/Pulse/First","affected":["Impact/Pulse/First Version 2: 1.1/2.15","impact_pulse_eco 1.16","BigVoice4 1.2","BigVoice2 1.30","Stream 1.1/2.4.29","WM2 1.11"],"ssvc":{"exploitation":"poc","automatable":"yes","technicalImpact":"partial","timestamp":"2025-12-22T21:56:07.247109Z"},"exploitAvailable":true,"published":"2025-12-22","updated":"2026-10-01","sourceUpdated":"2026-10-01T19:19:16.915Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2023-53964","references":[{"url":"https://www.exploit-db.com/exploits/51174","label":"ExploitDB-51174"},{"url":"https://web.archive.org/web/20221207074555/https://www.sound4.com/","label":"SOUND4 Official Product Homepage"},{"url":"https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5742.php","label":"Zero Science Lab Disclosure (ZSL-2022-5742)"},{"url":"https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-factory-reset-vulnerability","label":"VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability"}],"tags":["cve.org","exploit-available"],"epss":0.0098,"epssPercentile":0.6085,"ingestedAt":"2026-10-01T19:58:57.575Z","slug":"CVE-2023-53964","body":"## Overview\n\nSOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.\n\n## Affected\n\n- `Impact/Pulse/First Version 2: 1.1/2.15`\n- `impact_pulse_eco 1.16`\n- `BigVoice4 1.2`\n- `BigVoice2 1.30`\n- `Stream 1.1/2.4.29`\n- `WM2 1.11`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"abyssal","depthScore":66,"depthScoreParts":{"impact":53.9,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[]}