CRITICAL🇵🇱 Wersja polska

CVE-2022-50696

CVSS 9.3v4.0pub. 2025-12-30upd. 2026-01-16

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.

🤖 AI Analysis
How it works

Static authentication credentials (login and password) are embedded directly in the binary server files and cannot be changed during normal device operation. An attacker with knowledge of these credentials can log in to the device remotely over the network, completely bypassing access control mechanisms. The vulnerability affects both Linux and Windows environments, and exploitation does not require any user interaction or prior authentication.

Impact

An attacker can gain full unauthorized access to the device, which may lead to taking control of it, compromising the confidentiality and integrity of processed data, and potentially disrupting its operation.

Mitigation & patch

Apply patches available from the manufacturer according to the references. It is also recommended to isolate SOUND4 devices on the network (e.g., place behind a firewall, restrict network access only to trusted hosts) until updates are implemented.

Who is affected

SOUND4 IMPACT, SOUND4 FIRST, SOUND4 PULSE, SOUND4 Eco — versions 2.x and lower (including firmware variants for Sound4 Pulse Eco, Sound4 Big Voice2, Sound4 Big Voice4)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sound4 Big Voice2

    HW
    Sound4
    all versions
  • Sound4 Big Voice2 Firmware

    OS
    Sound4
    1.30
  • Sound4 Big Voice4

    HW
    Sound4
    all versions
  • Sound4 Big Voice4 Firmware

    OS
    Sound4
    1.2
  • Sound4 First

    HW
    Sound4
    1.02.0
  • Sound4 First Firmware

    OS
    Sound4
    1.692.15
  • Sound4 Impact

    HW
    Sound4
    1.02.0
  • Sound4 Impact Eco

    HW
    Sound4
    all versions
  • Sound4 Impact Eco Firmware

    OS
    Sound4
    1.16
  • Sound4 Impact Firmware

    OS
    Sound4
    1.692.15
  • Sound4 Pulse

    HW
    Sound4
    1.02.0
  • Sound4 Pulse Eco

    HW
    Sound4
    all versions
  • Sound4 Pulse Eco Firmware

    OS
    Sound4
    1.16
  • Sound4 Pulse Firmware

    OS
    Sound4
    1.692.15
  • Sound4 Stream Extension

    APP
    Sound4
    2.4.29
  • Sound4 Wm2

    HW
    Sound4
    all versions
  • Sound4 Wm2 Firmware

    OS
    Sound4
    1.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-50796CRITICAL9.3PL ✓same product

RCE i path traversal w firmware upload SOUND4 IMPACT/FIRST/PULSE/Eco

CVE-2022-50794CRITICAL9.3PL ✓same product

Command injection w parametrze username — SOUND4 IMPACT/FIRST/PULSE/Eco

CVE-2023-53960CRITICAL9.3PL ✓same product

SQL Injection w mechanizmie logowania SOUND4 IMPACT/FIRST/PULSE/Eco

CVE-2023-53955CRITICAL9.3PL ✓same product

IDOR w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x — pominięcie autoryzacji

CVE-2023-53963CRITICAL9.3PL ✓same product

Nieuwierzytelniony OS command injection w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x