CVE-2025-57431
22.09.2025, 17:16
The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.Enginsight
| Vendor | Product | Version |
|---|---|---|
| sound4 | pulse-eco_aes67_firmware | 1.22 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration