CVE-2022-50789 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

SOUND4 IMPACT/FIRST/PULSE/Eco
High CVSS: 8.5

CVE-2022-50789

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory with .dns.pid extension. Unauthenticated attackers can execute the malicious commands by making a single HTTP POST request to the vulnerable dns.php script, which triggers command execution and then deletes the file.
Vendor
Sound4
Product
Impact Firmware
CWE
CWE-78
Yayın Tarihi
2025-12-30 23:15:45
Güncelleme
2026-01-16 19:16:11
Source Identifier
disclosure@vulncheck.com
KEV Date Added
-

Kategoriler

Referanslar