CVE-2023-53962

HIGH

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2023-53962. PoCs published by LiquidWorm.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated directory traversal file write vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x devices. It allows arbitrary file uploads via the 'upgrade.php' script by manipulating the 'filename' parameter in a POST request.

Description

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated directory traversal vulnerability that allows remote attackers to write arbitrary files through the 'upgfile' parameter in upload.cgi. Attackers can exploit the vulnerability by sending crafted multipart form-data POST requests with directory traversal sequences to write files to unintended system locations.

Exploits (1)

exploitdb WORKING POC
by LiquidWorm · textlocalwindows
https://www.exploit-db.com/exploits/51172

This exploit demonstrates an unauthenticated directory traversal file write vulnerability in SOUND4 IMPACT/FIRST/PULSE/Eco v2.x devices. It allows arbitrary file uploads via the 'upgrade.php' script by manipulating the 'filename' parameter in a POST request.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x
No auth needed
Prerequisites: Network access to the target device · Target device running vulnerable SOUND4 software
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 7.5
EPSS 0.0104
EPSS Percentile 59.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (12)
sound4/big_voice2_firmware 1.30
sound4/big_voice4_firmware 1.2
sound4/first_firmware 2.15
sound4/first_firmware 1.69
sound4/impact_eco_firmware 1.16
sound4/impact_firmware 2.15
sound4/impact_firmware 1.69
sound4/pulse_eco_firmware 1.16
sound4/pulse_firmware 2.15
sound4/pulse_firmware 1.69
... and 2 more
Published Dec 22, 2025
Tracked Since Feb 18, 2026