Description
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/51168
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5722.php
www.exploit-db.com/exploits/51168 (ExploitDB-51168)
web.archive.org/web/20221207074555/https://www.sound4.com/ (SOUND4 Official Product Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5722.php (Zero Science Lab Disclosure (ZSL-2022-5722))
www.vulncheck.com/...stpulseeco-x-cross-site-request-forgery (VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Cross-Site Request Forgery)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.