SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound4 big Voice2
Sound4 big Voice2 Firmware Sound4 big Voice4 Sound4 big Voice4 Firmware Sound4 first Firmware Sound4 impact Eco Sound4 impact Eco Firmware Sound4 impact Firmware Sound4 pulse Sound4 pulse Eco Sound4 pulse Eco Firmware Sound4 pulse Firmware Sound4 stream Extension Sound4 wm2 Sound4 wm2 Firmware |
|
| CPEs | cpe:2.3:a:sound4:stream_extension:2.4.29:*:*:*:*:*:*:* cpe:2.3:h:sound4:big_voice2:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:big_voice4:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:first:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:first:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact_eco:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse_eco:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:wm2:-:*:*:*:*:*:*:* cpe:2.3:o:sound4:big_voice2_firmware:1.30:*:*:*:*:*:*:* cpe:2.3:o:sound4:big_voice4_firmware:1.2:*:*:*:*:*:*:* cpe:2.3:o:sound4:first_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:first_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_eco_firmware:1.16:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_eco_firmware:1.16:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:wm2_firmware:1.11:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sound4 big Voice2
Sound4 big Voice2 Firmware Sound4 big Voice4 Sound4 big Voice4 Firmware Sound4 first Firmware Sound4 impact Eco Sound4 impact Eco Firmware Sound4 impact Firmware Sound4 pulse Sound4 pulse Eco Sound4 pulse Eco Firmware Sound4 pulse Firmware Sound4 stream Extension Sound4 wm2 Sound4 wm2 Firmware |
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linux
Linux linux Microsoft Microsoft windows Sound4 Sound4 bigvoice2 Sound4 bigvoice4 Sound4 first Sound4 impact Sound4 pulse-eco Sound4 stream |
|
| Vendors & Products |
Linux
Linux linux Microsoft Microsoft windows Sound4 Sound4 bigvoice2 Sound4 bigvoice4 Sound4 first Sound4 impact Sound4 pulse-eco Sound4 stream |
Fri, 02 Jan 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 30 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers can leverage these static credentials to gain unauthorized access to the device across Linux and Windows distributions without requiring user interaction. | |
| Title | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Hardcoded Credentials Authentication Bypass | |
| Weaknesses | CWE-798 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-30T22:41:35.214Z
Updated: 2026-01-02T19:56:12.851Z
Reserved: 2025-12-21T19:48:13.436Z
Link: CVE-2022-50696
Updated: 2026-01-02T19:56:08.578Z
Status : Analyzed
Published: 2025-12-30T23:15:45.060
Modified: 2026-01-13T15:16:53.203
Link: CVE-2022-50696
No data.