SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.
The attacker sends an HTTP POST request to the 'index.php' file, injecting malicious SQL code into the 'password' parameter. The authentication mechanism does not properly filter input data, allowing manipulation of the SQL query that verifies login credentials. As a result, the query returns a positive result regardless of the actual password value, enabling unauthorized access to the system. A public exploit for this vulnerability is available on Exploit-DB.
An attacker can remotely and without authentication gain unauthorized access to the SOUND4 device management system. This results in complete compromise of the confidentiality and integrity of data accessible through the administrative panel.
Apply patches available from the manufacturer according to the references provided. Additionally, until the update is implemented, it is recommended to restrict access to the device's web interface only to trusted networks or IP addresses using a firewall, and to implement network segmentation.
SOUND4 IMPACT, SOUND4 FIRST, SOUND4 PULSE, SOUND4 Eco, SOUND4 Big Voice2, SOUND4 Big Voice4 — firmware version 2.x
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XSound4 Big Voice2
HWSound4all versionsSound4 Big Voice2 Firmware
OSSound41.30Sound4 Big Voice4
HWSound4all versionsSound4 Big Voice4 Firmware
OSSound41.2Sound4 First
HWSound41.02.0Sound4 First Firmware
OSSound41.692.15Sound4 Impact
HWSound41.02.0Sound4 Impact Eco
HWSound4all versionsSound4 Impact Eco Firmware
OSSound41.16Sound4 Impact Firmware
OSSound41.692.15Sound4 Pulse
HWSound41.02.0Sound4 Pulse Eco
HWSound4all versionsSound4 Pulse Eco Firmware
OSSound41.16Sound4 Pulse Firmware
OSSound41.692.15Sound4 Stream Extension
APPSound42.4.29Sound4 Wm2
HWSound4all versionsSound4 Wm2 Firmware
OSSound41.11
Related vulnerabilities
RCE i path traversal w firmware upload SOUND4 IMPACT/FIRST/PULSE/Eco
Command injection w parametrze username — SOUND4 IMPACT/FIRST/PULSE/Eco
Zakodowane na stałe dane logowania w urządzeniach SOUND4 IMPACT/FIRST/PULSE/Eco
IDOR w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x — pominięcie autoryzacji
Nieuwierzytelniony OS command injection w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x