CVE-2023-53961

MEDIUM

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - CSRF

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53961. PoCs published by LiquidWorm.

AI-analyzed exploit summary This PoC demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x, allowing an attacker to perform administrative actions (e.g., logo removal) via a malicious HTTP request if a logged-in user visits a crafted webpage.

Description

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textlocalwindows
https://www.exploit-db.com/exploits/51168

This PoC demonstrates a Cross-Site Request Forgery (CSRF) vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x, allowing an attacker to perform administrative actions (e.g., logo removal) via a malicious HTTP request if a logged-in user visits a crafted webpage.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x
Auth required
Prerequisites: Victim must be authenticated in the target application · Victim must visit a malicious webpage hosting the PoC
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit, Third Party Advisory, VDB Entry exploit
https://www.exploit-db.com/exploits/51168
Exploit, Third Party Advisory third-party-advisory
https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5722.php

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 5.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-352
Status published
Products (12)
sound4/big_voice2_firmware 1.30
sound4/big_voice4_firmware 1.2
sound4/first_firmware 2.15
sound4/first_firmware 1.69
sound4/impact_eco_firmware 1.16
sound4/impact_firmware 2.15
sound4/impact_firmware 1.69
sound4/pulse_eco_firmware 1.16
sound4/pulse_firmware 2.15
sound4/pulse_firmware 1.69
... and 2 more
Published Dec 22, 2025
Tracked Since Feb 18, 2026