CRITICAL🇵🇱 Wersja polska

CVE-2023-53960

CVSS 9.3v4.0pub. 2025-12-22upd. 2026-01-16

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.

🤖 AI Analysis
How it works

The attacker sends an HTTP POST request to the 'index.php' file, injecting malicious SQL code into the 'password' parameter. The authentication mechanism does not properly filter input data, allowing manipulation of the SQL query that verifies login credentials. As a result, the query returns a positive result regardless of the actual password value, enabling unauthorized access to the system. A public exploit for this vulnerability is available on Exploit-DB.

Impact

An attacker can remotely and without authentication gain unauthorized access to the SOUND4 device management system. This results in complete compromise of the confidentiality and integrity of data accessible through the administrative panel.

Mitigation & patch

Apply patches available from the manufacturer according to the references provided. Additionally, until the update is implemented, it is recommended to restrict access to the device's web interface only to trusted networks or IP addresses using a firewall, and to implement network segmentation.

Who is affected

SOUND4 IMPACT, SOUND4 FIRST, SOUND4 PULSE, SOUND4 Eco, SOUND4 Big Voice2, SOUND4 Big Voice4 — firmware version 2.x

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Sound4 Big Voice2

    HW
    Sound4
    all versions
  • Sound4 Big Voice2 Firmware

    OS
    Sound4
    1.30
  • Sound4 Big Voice4

    HW
    Sound4
    all versions
  • Sound4 Big Voice4 Firmware

    OS
    Sound4
    1.2
  • Sound4 First

    HW
    Sound4
    1.02.0
  • Sound4 First Firmware

    OS
    Sound4
    1.692.15
  • Sound4 Impact

    HW
    Sound4
    1.02.0
  • Sound4 Impact Eco

    HW
    Sound4
    all versions
  • Sound4 Impact Eco Firmware

    OS
    Sound4
    1.16
  • Sound4 Impact Firmware

    OS
    Sound4
    1.692.15
  • Sound4 Pulse

    HW
    Sound4
    1.02.0
  • Sound4 Pulse Eco

    HW
    Sound4
    all versions
  • Sound4 Pulse Eco Firmware

    OS
    Sound4
    1.16
  • Sound4 Pulse Firmware

    OS
    Sound4
    1.692.15
  • Sound4 Stream Extension

    APP
    Sound4
    2.4.29
  • Sound4 Wm2

    HW
    Sound4
    all versions
  • Sound4 Wm2 Firmware

    OS
    Sound4
    1.11
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLiAuth Bypass
CWE
References

Related vulnerabilities

CVE-2022-50796CRITICAL9.3PL ✓same product

RCE i path traversal w firmware upload SOUND4 IMPACT/FIRST/PULSE/Eco

CVE-2022-50794CRITICAL9.3PL ✓same product

Command injection w parametrze username — SOUND4 IMPACT/FIRST/PULSE/Eco

CVE-2022-50696CRITICAL9.3PL ✓same product

Zakodowane na stałe dane logowania w urządzeniach SOUND4 IMPACT/FIRST/PULSE/Eco

CVE-2023-53955CRITICAL9.3PL ✓same product

IDOR w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x — pominięcie autoryzacji

CVE-2023-53963CRITICAL9.3PL ✓same product

Nieuwierzytelniony OS command injection w SOUND4 IMPACT/FIRST/PULSE/Eco v2.x