SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.
The vulnerability results from a combination of a path traversal error (CWE-22) and lack of authentication in the upload.cgi script responsible for firmware uploads. An attacker can send a specially crafted request to the upload.cgi script containing a path traversal sequence that allows writing malicious files anywhere in the filesystem accessible to the www-data process. Files written this way can contain executable code, which can then be executed on the device, leading to system compromise.
Attackers gain the ability to write malicious files to the device with www-data privileges and execute arbitrary remote code without any authorization, resulting in unauthorized system access and potential complete device takeover.
Apply patches available from the manufacturer according to the references. As a temporary measure, it is recommended to restrict network access to the administrative interface of SOUND4 devices exclusively to trusted networks or hosts and isolate these devices from the public internet using a firewall.
SOUND4 IMPACT, SOUND4 FIRST, SOUND4 PULSE, SOUND4 Pulse Eco, SOUND4 Big Voice2, SOUND4 Big Voice4 — in firmware versions 2.x and earlier
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSound4 Big Voice2
HWSound4all versionsSound4 Big Voice2 Firmware
OSSound41.30Sound4 Big Voice4
HWSound4all versionsSound4 Big Voice4 Firmware
OSSound41.2Sound4 First
HWSound41.02.0Sound4 First Firmware
OSSound41.692.15Sound4 Impact
HWSound41.02.0Sound4 Impact Eco
HWSound4all versionsSound4 Impact Eco Firmware
OSSound41.16Sound4 Impact Firmware
OSSound41.692.15Sound4 Pulse
HWSound41.02.0Sound4 Pulse Eco
HWSound4all versionsSound4 Pulse Eco Firmware
OSSound41.16Sound4 Pulse Firmware
OSSound41.692.15Sound4 Stream Extension
APPSound42.4.29Sound4 Wm2
HWSound4all versionsSound4 Wm2 Firmware
OSSound41.11
Related vulnerabilities
Command injection w parametrze username — SOUND4 IMPACT/FIRST/PULSE/Eco
Zakodowane na stałe dane logowania w urządzeniach SOUND4 IMPACT/FIRST/PULSE/Eco
SQL Injection w mechanizmie logowania SOUND4 IMPACT/FIRST/PULSE/Eco
IDOR w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x — pominięcie autoryzacji
Nieuwierzytelniony OS command injection w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x