📦

first

Vendor: sound4

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 7 Remote Access
Total CVEs 57 Total Indexed
Avg. EPSS 0.96% Exploit Prob.
Latest CVE CVE-2022-50796 Dec 30

Security Vulnerability Index

Page 3 / 6
9.3 CVSS

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Attackers can exploit the vulnerability by manipulating user-supplied input to execute privileged functionalities without proper authentication.

EPSS: 0.38%
7.2 CVSS

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.

EPSS: 0.20%
7.5 CVSS

The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named functions (with the same signatures) in other tokens: First (FST), GG Token (GG), M2C Mesh Network (MTC), M2C Mesh Network (mesh), and UG Token (UGT).

EPSS: 0.34%