📦 Pulse Eco Firmware

by Sound4

🔍 What is Pulse Eco Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-50794

CRITICAL CVSS 9.8 Dec 30, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary system commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems by injecting shell commands through the username parameter in login sc...

CVE-2022-50796

CRITICAL CVSS 9.8 Dec 30, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary code on SOUND4 IMPACT/FIRST/PULSE/Eco systems by exploiting a path traversal flaw in the firmware upload functionality. Attacke...

CVE-2022-50696

CRITICAL CVSS 9.8 Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco devices versions 2.x and below contain hardcoded credentials in server binaries that cannot be changed through normal operations. Attackers can use these static credentia...

CVE-2022-50694

CRITICAL CVSS 9.8 Dec 30, 2025

This SQL injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems allows attackers to bypass authentication and potentially access sensitive database information by injecting malicious SQL cod...

CVE-2023-53960

CRITICAL CVSS 9.8 Dec 22, 2025

This SQL injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x allows attackers to bypass authentication by injecting malicious SQL code through the password parameter. Attackers can ga...

CVE-2023-53963

CRITICAL CVSS 9.8 Dec 22, 2025

CVE-2023-53963 is an unauthenticated remote command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x systems. Attackers can execute arbitrary shell commands with web server privileges by ...

CVE-2023-53964

CRITICAL CVSS 9.8 Dec 22, 2025

This vulnerability allows unauthenticated remote attackers to send a POST request to the /usr/cgi-bin/restorefactory.cgi endpoint to trigger a factory reset on SOUND4 IMPACT/FIRST/PULSE/Eco devices. T...

CVE-2023-53955

CRITICAL CVSS 9.8 Dec 22, 2025

This CVE describes an insecure direct object reference vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x systems that allows attackers to bypass authorization controls. By manipulating user-supplied...

CVE-2022-50792

HIGH CVSS 7.5 Dec 30, 2025

This vulnerability allows remote attackers to read arbitrary files on SOUND4 IMPACT/FIRST/PULSE/Eco devices without authentication by manipulating the 'file' GET parameter. Attackers can access sensit...

CVE-2022-50793

HIGH CVSS 8.8 Dec 30, 2025

This vulnerability allows authenticated attackers to execute arbitrary system commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems through command injection in the www-data-handler.php script. Attackers ...

CVE-2022-50795

HIGH CVSS 7.8 Dec 30, 2025

CVE-2022-50795 is a conditional command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems up to version 2.x. Unauthenticated attackers can execute arbitrary commands via a single HTTP P...

CVE-2022-50787

HIGH CVSS 7.2 Dec 30, 2025

CVE-2022-50787 is an unauthenticated stored cross-site scripting vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco software versions 2.x. Attackers can inject malicious scripts via the username parameter...

CVE-2022-50788

HIGH CVSS 7.5 Dec 30, 2025

CVE-2022-50788 is an information disclosure vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems that allows unauthenticated attackers to access sensitive log files by directly browsing the /log dir...

CVE-2022-50789

HIGH CVSS 7.8 Dec 30, 2025

This is a command injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco systems up to version 2.x. Local authenticated users can create malicious files in /tmp, then unauthenticated attackers can t...

CVE-2022-50790

HIGH CVSS 7.5 Dec 30, 2025

This vulnerability allows unauthenticated remote attackers to access live radio stream information from SOUND4 IMPACT/FIRST/PULSE/Eco systems. Attackers can exploit specific web scripts to disclose ra...

CVE-2022-50791

HIGH CVSS 7.8 Dec 30, 2025

This vulnerability allows unauthenticated attackers to execute arbitrary commands on SOUND4 IMPACT/FIRST/PULSE/Eco systems by sending a single HTTP POST request to the ping.php script. Attackers can c...

CVE-2022-50692

HIGH CVSS 7.5 Dec 30, 2025

SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below have insufficient session expiration, allowing attackers to reuse old session credentials. This enables session hijacking and unauthorized access t...

CVE-2022-50695

HIGH CVSS 7.5 Dec 30, 2025

This vulnerability allows unauthenticated attackers to abuse network diagnostic scripts (ping.php, traceroute.php, dns.php) in SOUND4 products to launch ICMP flood attacks against arbitrary external h...

CVE-2023-53965

HIGH CVSS 8.4 Dec 22, 2025

CVE-2023-53965 is an unquoted service path vulnerability in SOUND4 Server Service 4.1.102 that allows local non-privileged users to escalate privileges to LocalSystem level. Attackers can place malici...

CVE-2023-53962

HIGH CVSS 7.5 Dec 22, 2025

CVE-2023-53962 is an unauthenticated directory traversal vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x that allows remote attackers to write arbitrary files to unintended system locations via cr...

CVE-2023-53961

MEDIUM CVSS 4.3 Dec 22, 2025

This cross-site request forgery (CSRF) vulnerability in SOUND4 radio processing software allows attackers to trick authenticated administrators into performing unintended administrative actions. Attac...