SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected device.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound4 big Voice2
Sound4 big Voice2 Firmware Sound4 big Voice4 Sound4 big Voice4 Firmware Sound4 first Firmware Sound4 impact Eco Sound4 impact Eco Firmware Sound4 impact Firmware Sound4 pulse Sound4 pulse Eco Sound4 pulse Eco Firmware Sound4 pulse Firmware Sound4 stream Extension Sound4 wm2 Sound4 wm2 Firmware |
|
| CPEs | cpe:2.3:a:sound4:stream_extension:2.4.29:*:*:*:*:*:*:* cpe:2.3:h:sound4:big_voice2:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:big_voice4:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:first:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:first:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact_eco:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse_eco:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:wm2:-:*:*:*:*:*:*:* cpe:2.3:o:sound4:big_voice2_firmware:1.30:*:*:*:*:*:*:* cpe:2.3:o:sound4:big_voice4_firmware:1.2:*:*:*:*:*:*:* cpe:2.3:o:sound4:first_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:first_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_eco_firmware:1.16:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_eco_firmware:1.16:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:wm2_firmware:1.11:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sound4 big Voice2
Sound4 big Voice2 Firmware Sound4 big Voice4 Sound4 big Voice4 Firmware Sound4 first Firmware Sound4 impact Eco Sound4 impact Eco Firmware Sound4 impact Firmware Sound4 pulse Sound4 pulse Eco Sound4 pulse Eco Firmware Sound4 pulse Firmware Sound4 stream Extension Sound4 wm2 Sound4 wm2 Firmware |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Jan 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound4
Sound4 bigvoice2 Sound4 bigvoice4 Sound4 first Sound4 impact Sound4 pulse-eco Sound4 stream |
|
| Vendors & Products |
Sound4
Sound4 bigvoice2 Sound4 bigvoice4 Sound4 first Sound4 impact Sound4 pulse-eco Sound4 stream |
Tue, 30 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated file disclosure vulnerability that allows remote attackers to access sensitive system files. Attackers can exploit the vulnerability by manipulating the 'file' GET parameter to disclose arbitrary files on the affected device. | |
| Title | SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-30T22:41:37.875Z
Updated: 2026-01-05T20:17:56.939Z
Reserved: 2025-12-26T16:41:38.890Z
Link: CVE-2022-50792
Updated: 2026-01-05T20:17:54.405Z
Status : Analyzed
Published: 2025-12-30T23:15:46.077
Modified: 2026-01-13T14:40:40.103
Link: CVE-2022-50792
No data.