Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8hmq-qqfm-9gx3

Опубликовано: 23 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.8
CVSS3: 7.5

Описание

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.

EPSS

Процентиль: 80%
0.0133
Низкий

8.8 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.

EPSS

Процентиль: 80%
0.0133
Низкий

8.8 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-306