SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute arbitrary system commands with www-data user privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound4
Sound4 bigvoice2 Sound4 bigvoice4 Sound4 first Sound4 impact Sound4 pulse-eco Sound4 stream |
|
| Vendors & Products |
Sound4
Sound4 bigvoice2 Sound4 bigvoice4 Sound4 first Sound4 impact Sound4 pulse-eco Sound4 stream |
Tue, 30 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Attackers can exploit this vulnerability by crafting malicious 'services' parameter values to execute arbitrary system commands with www-data user privileges. | |
| Title | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php | |
| Weaknesses | CWE-78 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-30T22:41:38.291Z
Updated: 2026-01-05T20:18:24.581Z
Reserved: 2025-12-26T16:41:38.890Z
Link: CVE-2022-50793
Updated: 2026-01-05T20:18:22.095Z
Status : Awaiting Analysis
Published: 2025-12-30T23:15:46.247
Modified: 2025-12-31T20:42:43.210
Link: CVE-2022-50793
No data.