---
id: CVE-2023-53961
title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery
  vulnerability that allows attackers to perform administrative actions without
  user consent. Attackers can craft malicious web pages that submit HTTP
  requests to the…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-352
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2025-12-22T21:56:35.779386Z'
exploitAvailable: true
published: '2025-12-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:15.019Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-53961'
references:
  - url: 'https://www.exploit-db.com/exploits/51168'
    label: ExploitDB-51168
  - url: 'https://web.archive.org/web/20221207074555/https://www.sound4.com/'
    label: SOUND4 Official Product Homepage
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5722.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5722)
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-cross-site-request-forgery
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request
      Forgery
tags:
  - cve.org
  - exploit-available
epss: 0.00193
epssPercentile: 0.08131
ingestedAt: '2026-10-01T19:58:57.576Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
