Metrics
Affected Vendors & Products
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound4
Sound4 first Sound4 impact Sound4 pulse-eco |
|
| Vendors & Products |
Sound4
Sound4 first Sound4 impact Sound4 pulse-eco |
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit the login.php and index.php scripts by injecting shell commands via the 'password' POST parameter to execute commands with web server privileges. | |
| Title | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-22T22:03:29.168Z
Reserved: 2025-12-19T14:03:57.724Z
Link: CVE-2023-53963
Updated: 2025-12-22T21:56:19.420Z
Status : Awaiting Analysis
Published: 2025-12-22T22:16:00.693
Modified: 2025-12-23T14:51:52.650
Link: CVE-2023-53963
No data.