Sound4
sound4
25 CVEs • 38 products
Products (38)
Click to collapseToggle
Products (38)
Click to collapse
CVEs (25)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write mali...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute comm...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 13, 2026 Dec 30, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login.php scripts by injecting arbitrary shel...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 13, 2026 Dec 30, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands through the 'services' POST parameter. Atta...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by mani...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Unauthenticated attackers can execute comm...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated vulnerability that allows remote attackers to access live radio stream information through webplay or ffmpeg scripts. Attackers can exploit...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 8.5 HIGH· v4 7.8 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 13, 2026 Dec 30, 2025 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve syste...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 13, 2026 Dec 30, 2025 5.3 MEDIUM· v4 7.2 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains an unauthenticated stored cross-site scripting vulnerability in the username parameter that allows attackers to inject malicious scripts. Attackers can exploit the unva...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x contains a network vulnerability that allows unauthenticated attackers to send ICMP signals to arbitrary hosts through network command scripts. Attackers can abuse ping.php, tra...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 30, 2025 8.8 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Attackers can inject arbitrary SQL code thro...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 20, 2026 Dec 30, 2025 6.9 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an insufficient session expiration vulnerability that allows attackers to reuse old session credentials. Attackers can exploit weak session management to poten...Show more |
1Sound4 1Linkandshare Transmitter Dec 31, 2025 Dec 22, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 LinkAndShare Transmitter 1.1.2 contains a format string vulnerability that allows attackers to trigger memory stack overflows through maliciously crafted environment variables. Attackers can manipulate the usernam...Show more |
1Sound4 15Big Voice Firmware First FirmwareImpact Eco Firmware+12 moreJan 29, 2026 Dec 22, 2025 8.6 HIGH· v4 7.8 HIGH· v3 N/A· v2 SOUND4 Server Service 4.1.102 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted binary...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 22, 2025 8.8 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request t...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 13, 2026 Dec 22, 2025 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'password' parameter. Attackers can exploit t...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 22, 2025 8.8 HIGH· v4 7.5 HIGH· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit...Show more |
1Sound4 9Big Voice2 Firmware Big Voice4 FirmwareFirst Firmware+6 moreJan 16, 2026 Dec 22, 2025 5.1 MEDIUM· v4 4.3 MEDIUM· v3 N/A· v2 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTT...Show more |