CVE-2022-50788: SOUND4 Big VOICE2 Firmware
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.
Affected products
- SOUND4 Big VOICE2 Firmware: version 1.30 only
- SOUND4 Big VOICE4 Firmware: version 1.2 only
- SOUND4 First Firmware: version 2.15 only; version 1.69 only
- SOUND4 Impact Eco Firmware: version 1.16 only
- SOUND4 Impact Firmware: version 2.15 only; version 1.69 only
- SOUND4 Pulse Eco Firmware: version 1.16 only
- SOUND4 Pulse Firmware: version 2.15 only; version 1.69 only
- SOUND4 Stream Extension: version 2.4.29 only
- SOUND4 WM2 Firmware: version 1.11 only
Published 2025-12-30. Last modified 2026-06-17.