---
id: CVE-2022-50794
title: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via
  Username
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an
  unauthenticated command injection vulnerability in the username parameter.
  Attackers can exploit index.php and login.php scripts by injecting arbitrary
  shell commands throug…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-78
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-01-05T20:18:46.413679Z'
exploitAvailable: true
published: '2025-12-30'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:11.695Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2022-50794'
references:
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5739.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5739)
  - url: >-
      https://packetstormsecurity.com/files/170266/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-username-Command-Injection.html
    label: Packet Storm Security Exploit Details
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/247914'
    label: IBM X-Force Vulnerability Exchange Entry
  - url: 'https://www.sound4.com/'
    label: SOUND4 Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-command-injection-via-username
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated
      Command Injection via Username
tags:
  - cve.org
  - exploit-available
epss: 0.03659
epssPercentile: 0.89263
ingestedAt: '2026-10-01T19:58:57.577Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
