SOUND4 Impact, Pulse, First, and Eco Unauthenticated Radio Stream Disclosure Vulnerability

Vulnerability

A vulnerability exists in SOUND4 IMPACT, FIRST, PULSE, and Eco versions 2.x and below, allowing remote attackers to access live radio stream information without authentication. This is achieved by calling specific web scripts, such as through webplay or ffmpeg, to disclose details about the radio stream.

Impact

Exploitation of this vulnerability leads to unauthorized access to sensitive information, specifically live radio stream details.

Reproduction

The vulnerability can be reproduced by sending a request to the server that includes the targeted webplay or ffmpeg script. This can be done using a web browser or a command-line tool that supports HTTP requests. The server response will include the live radio stream information, demonstrating the successful exploitation of the vulnerability.

Added: Dec 30, 2025, 11:45 PM
Updated: Dec 30, 2025, 11:45 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.