VulnSea

Impact/Pulse/First vulnerabilities

CVEs whose affected-version data names the Impact/Pulse/First package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

19 CVEsRSS

CVE-2022-50696Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.60%via CVEORG
CVE-2022-50692High· 7.5PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to potentially hijack act…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.58%via CVEORG
CVE-2022-50789High· 7.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malic…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 4.2%via CVEORG
CVE-2022-50695High· 7.5PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, traceroute.php, and …

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.80%via CVEORG
CVE-2022-50694Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code through the username …

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.89%via CVEORG
CVE-2022-50790High· 7.5PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit the vulnerability…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.79%via CVEORG
CVE-2022-50788High· 7.5PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive i…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.83%via CVEORG
CVE-2022-50787High· 7.2PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unvalidated username …

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.44%via CVEORG
CVE-2022-50791High· 7.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a …

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.8%via CVEORG
CVE-2022-50795High· 7.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute commands by making a …

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 4.2%via CVEORG
CVE-2022-50793High· 8.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.1%via CVEORG
CVE-2022-50792High· 7.5PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'fil…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 1.6%via CVEORG
CVE-2022-50794Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands throug…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.7%via CVEORG
CVE-2023-53960Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x SQL Injection via Authentication Bypass

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'pas…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.74%via CVEORG
CVE-2023-53955Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.85%via CVEORG
CVE-2023-53962High· 7.5PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability…

▾ MidnightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 1.2%via CVEORG
CVE-2023-53961Medium· 4.3PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the…

▾ TwilightSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.19%via CVEORG
CVE-2023-53964Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint wi…

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 0.98%via CVEORG
CVE-2023-53963Critical· 9.8PoC
9mo ago

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and …

▾ AbyssalSOUND4 Ltd. · Impact/Pulse/FirstEPSS 3.4%via CVEORG
Impact/Pulse/First vulnerabilities (CVEs) · VulnSea