SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shell commands through the HTTP POST 'username' parameter to execute system commands.
The vulnerability is located in the 'username' parameter transmitted via HTTP POST method to the index.php and login.php scripts. The application does not properly sanitize user-supplied input data, which enables injection of arbitrary system shell commands. Since the vulnerability is available without authentication, an attacker can exploit it directly over the network without any prior login.
An attacker can execute arbitrary system commands with the privileges of the process handling the application, which may lead to complete device takeover, data leakage, and violation of system availability and integrity.
Apply patches available from the manufacturer according to the references. It is recommended to update device firmware to a version higher than 2.x and restrict network access to the SOUND4 device management interface exclusively to trusted hosts or networks (e.g., through firewall or network segmentation).
SOUND4 IMPACT, SOUND4 FIRST, SOUND4 PULSE, SOUND4 Pulse Eco — versions 2.x and lower
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSound4 Big Voice2
HWSound4all versionsSound4 Big Voice2 Firmware
OSSound41.30Sound4 Big Voice4
HWSound4all versionsSound4 Big Voice4 Firmware
OSSound41.2Sound4 First
HWSound41.02.0Sound4 First Firmware
OSSound41.692.15Sound4 Impact
HWSound41.02.0Sound4 Impact Eco
HWSound4all versionsSound4 Impact Eco Firmware
OSSound41.16Sound4 Impact Firmware
OSSound41.692.15Sound4 Pulse
HWSound41.02.0Sound4 Pulse Eco
HWSound4all versionsSound4 Pulse Eco Firmware
OSSound41.16Sound4 Pulse Firmware
OSSound41.692.15Sound4 Stream Extension
APPSound42.4.29Sound4 Wm2
HWSound4all versionsSound4 Wm2 Firmware
OSSound41.11
Related vulnerabilities
RCE i path traversal w firmware upload SOUND4 IMPACT/FIRST/PULSE/Eco
Zakodowane na stałe dane logowania w urządzeniach SOUND4 IMPACT/FIRST/PULSE/Eco
SQL Injection w mechanizmie logowania SOUND4 IMPACT/FIRST/PULSE/Eco
IDOR w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x — pominięcie autoryzacji
Nieuwierzytelniony OS command injection w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x