Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Impact/Pulse/First — Vulnerabilities & Security Advisories 20

All 20 CVE vulnerabilities found in Impact/Pulse/First, with AI-generated Chinese analysis, references, and POCs.

Vendor: SOUND4 Ltd.

CVE IDTitleCVSSSeverityPublished
CVE-2022-50796 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi CWE-22 9.8 Critical2025-12-30
CVE-2022-50794 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Command Injection via Username CWE-78 9.8 Critical2025-12-30
CVE-2022-50795 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via traceroute.php CWE-78 7.8 High2025-12-30
CVE-2022-50793 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Authenticated Command Injection via www-data-handler.php CWE-78 8.8 High2025-12-30
CVE-2022-50792 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability CWE-22 7.5 High2025-12-30
CVE-2022-50791 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via ping.php CWE-78 7.8 High2025-12-30
CVE-2022-50789 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Conditional Command Injection via dns.php CWE-78 7.8 High2025-12-30
CVE-2022-50790 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Radio Stream Disclosure CWE-306 7.5 High2025-12-30
CVE-2022-50787 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Stored Cross-Site Scripting CWE-79 7.2 High2025-12-30
CVE-2022-50788 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory CWE-548 7.5 High2025-12-30
CVE-2022-50695 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x ICMP Flood Attack via Network Commands CWE-770 7.5 High2025-12-30
CVE-2022-50696 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass CWE-798 9.8 Critical2025-12-30
CVE-2022-50694 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x SQL Injection via Username Parameter CWE-89 9.8 Critical2025-12-30
CVE-2022-50692 SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Insufficient Session Expiration Vulnerability CWE-613 7.5 High2025-12-30
CVE-2023-53962 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Directory Traversal File Write CWE-22 7.5 High2025-12-22
CVE-2023-53963 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection CWE-78 9.8 Critical2025-12-22
CVE-2023-53964 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability CWE-306 9.8 Critical2025-12-22
CVE-2023-53961 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery CWE-352 4.3 Medium2025-12-22
CVE-2023-53960 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x SQL Injection via Authentication Bypass CWE-89 9.8 Critical2025-12-22
CVE-2023-53955 SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Authorization Bypass via Insecure Object References CWE-639 9.8 Critical2025-12-22

All 20 known CVE vulnerabilities affecting Impact/Pulse/First with full Chinese analysis, references, and POCs where available.