---
id: CVE-2023-53962
title: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File
  Write
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory
  traversal vulnerability that allows remote attackers to write arbitrary files
  through the 'upgfile' parameter in upload.cgi. Attackers can exploit the
  vulnerability…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cvssSource: cna
cwe:
  - CWE-22
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-12-22T21:56:24.694055Z'
exploitAvailable: true
published: '2025-12-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:15.672Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-53962'
references:
  - url: 'https://www.exploit-db.com/exploits/51172'
    label: ExploitDB-51172
  - url: 'https://web.archive.org/web/20221207074555/https://www.sound4.com/'
    label: SOUND4 Official Product Homepage
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5730.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5730)
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-directory-traversal-file-write
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated
      Directory Traversal File Write
tags:
  - cve.org
  - exploit-available
epss: 0.01238
epssPercentile: 0.67997
ingestedAt: '2026-10-01T19:58:57.576Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal sequences to write files to unintended system locations.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
