SOUND4 Impact
- <= 2.x
- 1.1
- 2.15
- 2.1
- 1.69
- 1.16
- 1.2
- 1.30
- 2.4.29
- 1.11
A remote code execution vulnerability has been identified in SOUND4 IMPACT, FIRST, PULSE, and ECO products, specifically in versions 2.x and prior. The issue arises from the firmware upload functionality, which contains a path traversal flaw, allowing attackers to exploit the upload.cgi script. This exploitation enables the unauthorized writing of malicious files to the system with www-data permissions, facilitating unauthorized access and code execution.
Exploitation of this vulnerability allows for unauthenticated remote code execution on the affected system, with the executed code running under the www-data user.
The vulnerability can be reproduced by sending a specially crafted request to the upload.cgi script. This request must exploit the path traversal flaw to write a malicious file to a location on the system where it can be executed. The uploaded file will need to be crafted to include a payload that, when executed, provides a reverse shell or similar access back to the attacker.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.