---
id: CVE-2022-50696
title: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication
  Bypass
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded
  credentials embedded in server binaries that cannot be modified through normal
  device operations. Attackers can leverage these static credentials to gain
  unauthorized…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-798
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-03-04T19:29:43.261231Z'
exploitAvailable: true
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:06.504Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2022-50696'
references:
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5729.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5729)
  - url: >-
      https://packetstormsecurity.com/files/170256/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-Hardcoded-Credentials.html
    label: Packet Storm Security Exploit Details
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/247949'
    label: IBM X-Force Vulnerability Exchange Entry
  - url: 'https://www.sound4.com/'
    label: SOUND4 Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-hardcoded-credentials-authentication-bypass
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded
      Credentials Authentication Bypass
tags:
  - cve.org
  - exploit-available
epss: 0.00596
epssPercentile: 0.46508
ingestedAt: '2026-10-01T19:58:57.582Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
