---
id: CVE-2023-53964
title: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability
summary: >-
  SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability
  in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers
  to reset device configuration. Attackers can send a POST request to the
  endpoint wi…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cvssSource: cna
cwe:
  - CWE-306
vendor: SOUND4 Ltd.
product: Impact/Pulse/First
affected:
  - 'Impact/Pulse/First Version 2: 1.1/2.15'
  - impact_pulse_eco 1.16
  - BigVoice4 1.2
  - BigVoice2 1.30
  - Stream 1.1/2.4.29
  - WM2 1.11
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2025-12-22T21:56:07.247109Z'
exploitAvailable: true
published: '2025-12-22'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T19:19:16.915Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2023-53964'
references:
  - url: 'https://www.exploit-db.com/exploits/51174'
    label: ExploitDB-51174
  - url: 'https://web.archive.org/web/20221207074555/https://www.sound4.com/'
    label: SOUND4 Official Product Homepage
  - url: 'https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5742.php'
    label: Zero Science Lab Disclosure (ZSL-2022-5742)
  - url: >-
      https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-factory-reset-vulnerability
    label: >-
      VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated
      Factory Reset Vulnerability
tags:
  - cve.org
  - exploit-available
epss: 0.0098
epssPercentile: 0.6085
ingestedAt: '2026-10-01T19:58:57.575Z'
---

## Overview

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.

## Affected

- `Impact/Pulse/First Version 2: 1.1/2.15`
- `impact_pulse_eco 1.16`
- `BigVoice4 1.2`
- `BigVoice2 1.30`
- `Stream 1.1/2.4.29`
- `WM2 1.11`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
