CVE-2022-50789: SOUND4 Big VOICE2 Firmware

High severity, CVSS 7.8. EPSS: 4.2% chance of exploitation in the next 30 days.

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malicious commands by making a single HTTP POST request to the vulnerable dns.php script, which triggers command execution and then deletes the file.

Affected products

  • SOUND4 Big VOICE2 Firmware: version 1.30 only
  • SOUND4 Big VOICE4 Firmware: version 1.2 only
  • SOUND4 First Firmware: version 2.15 only; version 1.69 only
  • SOUND4 Impact Eco Firmware: version 1.16 only
  • SOUND4 Impact Firmware: version 2.15 only; version 1.69 only
  • SOUND4 Pulse Eco Firmware: version 1.16 only
  • SOUND4 Pulse Firmware: version 2.15 only; version 1.69 only
  • SOUND4 Stream Extension: version 2.4.29 only
  • SOUND4 WM2 Firmware: version 1.11 only

Published 2025-12-30. Last modified 2026-06-17.