---
id: CVE-2022-50793
title: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via
  www-data-handler.php
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command
  injection vulnerability in the www-data-handler.php script that allows
  attackers to inject system commands through the 'services' POST parameter.
  Attackers can exploit…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-78
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-01-05T20:18:18.541233Z'
exploitAvailable: true
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:11.069Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2022-50793'
references:
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5737.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5737)
  - url: >-
      https://packetstormsecurity.com/files/170264/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-services-Command-Injection.html
    label: Packet Storm Security Exploit Details
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/247917'
    label: IBM X-Force Vulnerability Exchange Entry
  - url: 'https://www.sound4.com/'
    label: SOUND4 Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-authenticated-command-injection-via-www-data-handlerphp
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated
      Command Injection via www-data-handler.php
tags:
  - cve.org
  - exploit-available
epss: 0.03127
epssPercentile: 0.87407
ingestedAt: '2026-10-01T19:58:57.578Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute arbitrary system commands with www-data user privileges.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
