CVE-2023-53960

CRITICAL

SOUND4 IMPACT/FIRST/PULSE/Eco 2.x - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53960. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates an SQL injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x, allowing authentication bypass via the 'password' POST parameter in 'index.php'. The provided payload manipulates the SQL query to bypass authentication.

Description

SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. Attackers can inject malicious SQL code through the 'password' POST parameter to bypass authentication and potentially gain unauthorized access to the system.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textlocalwindows
https://www.exploit-db.com/exploits/51171

This exploit demonstrates an SQL injection vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x, allowing authentication bypass via the 'password' POST parameter in 'index.php'. The provided payload manipulates the SQL query to bypass authentication.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x
No auth needed
Prerequisites: Network access to the target application · SQL injection vulnerability in the 'password' parameter
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 9.8
EPSS 0.0066
EPSS Percentile 46.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (12)
sound4/big_voice2_firmware 1.30
sound4/big_voice4_firmware 1.2
sound4/first_firmware 2.15
sound4/first_firmware 1.69
sound4/impact_eco_firmware 1.16
sound4/impact_firmware 2.15
sound4/impact_firmware 1.69
sound4/pulse_eco_firmware 1.16
sound4/pulse_firmware 2.15
sound4/pulse_firmware 1.69
... and 2 more
Published Dec 22, 2025
Tracked Since Feb 18, 2026