---
id: CVE-2022-50796
title: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code
  execution vulnerability in the firmware upload functionality with path
  traversal flaw
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code
  execution vulnerability in the firmware upload functionality with path
  traversal flaw. Attackers can exploit the upload.cgi script to write malicious
  files to th…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: sound4
product: stream_extension
affected:
  - impact_firmware = 2.15
  - impact_firmware = 1.69
  - pulse_firmware = 2.15
  - pulse_firmware = 1.69
  - first_firmware = 2.15
  - first_firmware = 1.69
  - impact_eco_firmware = 1.16
  - pulse_eco_firmware = 1.16
  - big_voice4_firmware = 1.2
  - big_voice2_firmware = 1.30
  - wm2_firmware = 1.11
  - stream_extension = 2.4.29
published: '2025-12-30'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T23:10:00.133'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-50796'
references:
  - url: 'https://exchange.xforce.ibmcloud.com/vulnerabilities/247951'
    label: disclosure@vulncheck.com
  - url: >-
      https://packetstormsecurity.com/files/170268/SOUND4-IMPACT-FIRST-PULSE-Eco-2.x-upload.cgi-Code-Execution.html
    label: disclosure@vulncheck.com
  - url: 'https://www.sound4.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-remote-code-execution-via-uploadcgi
    label: disclosure@vulncheck.com
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5741.php'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.01591
epssPercentile: 0.74584
ingestedAt: '2026-09-24T23:55:20.488Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.

## Affected

- `impact_firmware = 2.15`
- `impact_firmware = 1.69`
- `pulse_firmware = 2.15`
- `pulse_firmware = 1.69`
- `first_firmware = 2.15`
- `first_firmware = 1.69`
- `impact_eco_firmware = 1.16`
- `pulse_eco_firmware = 1.16`
- `big_voice4_firmware = 1.2`
- `big_voice2_firmware = 1.30`
- `wm2_firmware = 1.11`
- `stream_extension = 2.4.29`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
