Executive brief
SOUND4 IMPACT, FIRST, PULSE, and Eco are audio equipment devices with firmware management interfaces. Attackers can upload malicious firmware or files without authentication, gaining the ability to execute arbitrary code on the devices, potentially compromising audio playback systems, data integrity, and network access.
Technical details
The vulnerability is an unauthenticated remote code execution in the firmware upload functionality (upload.cgi script) affecting SOUND4 IMPACT/FIRST/PULSE/Eco devices running version 2.x and earlier. The vulnerability involves a path traversal flaw that allows attackers to upload malicious files and write them to arbitrary locations on the system with www-data permissions. No authentication is required to exploit this vulnerability, and the attack is network-accessible. Successful exploitation enables full code execution on the affected device.
Affected products
- SOUND4 IMPACT <=2.x
- SOUND4 FIRST <=2.x
- SOUND4 PULSE <=2.x
- SOUND4 Eco <=2.x
Timeline
- 2025-12-30: disclosed