---
id: CVE-2023-53963
title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command
  injection vulnerability that allows remote attackers to execute arbitrary
  shell commands through the 'password' parameter. Attackers can exploit the
  login.php and …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-78
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2025-12-22T21:56:16.358655Z'
exploitAvailable: true
published: '2025-12-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:16.320Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-53963'
references:
  - url: 'https://www.exploit-db.com/exploits/51173'
    label: ExploitDB-51173
  - url: 'https://web.archive.org/web/20221207074555/https://www.sound4.com/'
    label: SOUND4 Official Product Homepage
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5738.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5738)
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-remote-command-injection
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated
      Remote Command Injection
tags:
  - cve.org
  - exploit-available
epss: 0.03397
epssPercentile: 0.88436
ingestedAt: '2026-10-01T19:58:57.574Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
