SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.
Static authentication credentials (login and password) are embedded directly in the binary server files and cannot be changed during normal device operation. An attacker with knowledge of these credentials can log in to the device remotely over the network, completely bypassing access control mechanisms. The vulnerability affects both Linux and Windows environments, and exploitation does not require any user interaction or prior authentication.
An attacker can gain full unauthorized access to the device, which may lead to taking control of it, compromising the confidentiality and integrity of processed data, and potentially disrupting its operation.
Apply patches available from the manufacturer according to the references. It is also recommended to isolate SOUND4 devices on the network (e.g., place behind a firewall, restrict network access only to trusted hosts) until updates are implemented.
SOUND4 IMPACT, SOUND4 FIRST, SOUND4 PULSE, SOUND4 Eco — versions 2.x and lower (including firmware variants for Sound4 Pulse Eco, Sound4 Big Voice2, Sound4 Big Voice4)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSound4 Big Voice2
HWSound4all versionsSound4 Big Voice2 Firmware
OSSound41.30Sound4 Big Voice4
HWSound4all versionsSound4 Big Voice4 Firmware
OSSound41.2Sound4 First
HWSound41.02.0Sound4 First Firmware
OSSound41.692.15Sound4 Impact
HWSound41.02.0Sound4 Impact Eco
HWSound4all versionsSound4 Impact Eco Firmware
OSSound41.16Sound4 Impact Firmware
OSSound41.692.15Sound4 Pulse
HWSound41.02.0Sound4 Pulse Eco
HWSound4all versionsSound4 Pulse Eco Firmware
OSSound41.16Sound4 Pulse Firmware
OSSound41.692.15Sound4 Stream Extension
APPSound42.4.29Sound4 Wm2
HWSound4all versionsSound4 Wm2 Firmware
OSSound41.11
Related vulnerabilities
RCE i path traversal w firmware upload SOUND4 IMPACT/FIRST/PULSE/Eco
Command injection w parametrze username — SOUND4 IMPACT/FIRST/PULSE/Eco
SQL Injection w mechanizmie logowania SOUND4 IMPACT/FIRST/PULSE/Eco
IDOR w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x — pominięcie autoryzacji
Nieuwierzytelniony OS command injection w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x