SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.
Metrics
Affected Vendors & Products
References
History
Tue, 13 Jan 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound4 big Voice2
Sound4 big Voice2 Firmware Sound4 big Voice4 Sound4 big Voice4 Firmware Sound4 first Firmware Sound4 impact Eco Sound4 impact Eco Firmware Sound4 impact Firmware Sound4 pulse Sound4 pulse Eco Sound4 pulse Eco Firmware Sound4 pulse Firmware Sound4 stream Extension Sound4 wm2 Sound4 wm2 Firmware |
|
| CPEs | cpe:2.3:a:sound4:stream_extension:2.4.29:*:*:*:*:*:*:* cpe:2.3:h:sound4:big_voice2:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:big_voice4:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:first:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:first:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:impact_eco:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse:1.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse:2.0:*:*:*:*:*:*:* cpe:2.3:h:sound4:pulse_eco:-:*:*:*:*:*:*:* cpe:2.3:h:sound4:wm2:-:*:*:*:*:*:*:* cpe:2.3:o:sound4:big_voice2_firmware:1.30:*:*:*:*:*:*:* cpe:2.3:o:sound4:big_voice4_firmware:1.2:*:*:*:*:*:*:* cpe:2.3:o:sound4:first_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:first_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_eco_firmware:1.16:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:impact_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_eco_firmware:1.16:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_firmware:1.69:*:*:*:*:*:*:* cpe:2.3:o:sound4:pulse_firmware:2.15:*:*:*:*:*:*:* cpe:2.3:o:sound4:wm2_firmware:1.11:*:*:*:*:*:*:* |
|
| Vendors & Products |
Sound4 big Voice2
Sound4 big Voice2 Firmware Sound4 big Voice4 Sound4 big Voice4 Firmware Sound4 first Firmware Sound4 impact Eco Sound4 impact Eco Firmware Sound4 impact Firmware Sound4 pulse Sound4 pulse Eco Sound4 pulse Eco Firmware Sound4 pulse Firmware Sound4 stream Extension Sound4 wm2 Sound4 wm2 Firmware |
Tue, 23 Dec 2025 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sound4
Sound4 first Sound4 impact Sound4 pulse-eco |
|
| Vendors & Products |
Sound4
Sound4 first Sound4 impact Sound4 pulse-eco |
Mon, 22 Dec 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control. | |
| Title | SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Factory Reset Vulnerability | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-22T21:37:17.482Z
Updated: 2025-12-22T22:03:24.021Z
Reserved: 2025-12-19T14:03:57.724Z
Link: CVE-2023-53964
Updated: 2025-12-22T21:56:10.266Z
Status : Analyzed
Published: 2025-12-22T22:16:00.860
Modified: 2026-01-13T15:40:47.380
Link: CVE-2023-53964
No data.