Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hv34-rhhr-q53f

Опубликовано: 31 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 7.5

Описание

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.

EPSS

Процентиль: 79%
0.01302
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 месяца назад

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exploit the upload.cgi script to write malicious files to the system with www-data permissions, enabling unauthorized access and code execution.

EPSS

Процентиль: 79%
0.01302
Низкий

9.3 Critical

CVSS4

7.5 High

CVSS3

Дефекты

CWE-22