← Back

CVE-2023-53962

nvd nist
Published: Dec 22, 2025Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal sequences to write files to unintended system locations.

Affected (12)

9 products
Impact Firmware
Pulse Firmware
First Firmware
Stream Extension
Wm2 Firmware
Big Voice2 Firmware
Big Voice4 Firmware
Pulse Eco Firmware
Impact Eco Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.15
Running on/withPlatform Versions
Sound4
Impact
Version 2.0
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.69
Running on/withPlatform Versions
Sound4
Impact
Version 1.0
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.15
Running on/withPlatform Versions
Sound4
Pulse
Version 2.0
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.69
Running on/withPlatform Versions
Sound4
Pulse
Version 1.0
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 2.15
Running on/withPlatform Versions
Sound4
First
Version 2.0
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.69
Running on/withPlatform Versions
Sound4
First
Version 1.0
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.4.29
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.11
Running on/withPlatform Versions
Sound4
Wm2
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.30
Running on/withPlatform Versions
Sound4
Big Voice2
All versions
Configuration J
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.2
Running on/withPlatform Versions
Sound4
Big Voice4
All versions
Configuration K
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.16
Running on/withPlatform Versions
Sound4
Pulse Eco
All versions
Configuration L
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 1.16
Running on/withPlatform Versions
Sound4
Impact Eco
All versions

References (5)

Source: disclosure@vulncheck.com
ExploitThird Party AdvisoryVDB Entry
Source: disclosure@vulncheck.com
ExploitThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
ExploitThird Party Advisory

Timeline

No history available yet.