CVE-2023-53964

EUVD-2023-60249
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
VulnCheckCNA
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
Affected Products (NVD)
VendorProductVersion
sound4impact_firmware
2.15
sound4impact_firmware
1.69
sound4pulse_firmware
2.15
sound4pulse_firmware
1.69
sound4first_firmware
2.15
sound4first_firmware
1.69
sound4impact_eco_firmware
1.16
sound4pulse_eco_firmware
1.16
sound4big_voice4_firmware
1.2
sound4big_voice2_firmware
1.30
sound4wm2_firmware
1.11
sound4stream_extension
2.4.29
𝑥
= Vulnerable software versions