CVE-2022-50796
7.5SOUND4 Ltd. · IMPACT, FIRST, PULSE, Eco, BigVoice4, BigVoice2, Stream, and Kantar Media WM2
An unauthenticated remote code execution vulnerability exists in the firmware upload functionality of various SOUND4 products due to a path traversal flaw in the upload.cgi script.
Executive summary
SOUND4 and associated broadcast audio products are vulnerable to unauthenticated remote code execution, posing a critical risk of full system compromise.
Vulnerability
The vulnerability stems from an improper path traversal flaw within the upload.cgi script, which allows unauthenticated remote attackers to upload and execute malicious files on the underlying system with www-data permissions.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code on these broadcast devices presents a severe risk to operational continuity. Successful exploitation could lead to total unauthorized control over the audio processing environment, potentially resulting in unauthorized broadcast manipulation or complete system takeover. With a CVSS score of 7.5, this high-severity flaw necessitates immediate attention to prevent malicious actors from gaining a foothold in the infrastructure.
Remediation
Immediate Action: Identify all instances of the affected SOUND4 firmware and update them to the latest vendor-supplied versions immediately.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed toward the upload.cgi endpoint and review system logs for unauthorized file creation or execution attempts.
Compensating Controls: Implement strict firewall rules to restrict access to the device management interface to trusted administrative IP addresses only, effectively blocking unauthenticated external access.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the Packet Storm Security reference.
Analyst recommendation
The presence of a public proof-of-concept and the lack of authentication required for exploitation make this vulnerability an urgent priority. Organizations deploying these audio processing units should verify their firmware versions immediately and apply available updates. If an update cannot be performed, restrict network access to the device interfaces to prevent remote exploitation.
Sources
Originally found and disclosed by LiquidWorm as Gjoko Krstic of Zero Science Lab, per the CVE Program record.
- Zero Science Lab Disclosure (ZSL-2022-5741) Third-party advisory
- Packet Storm Security Exploit Details Exploit / PoC
- IBM X-Force Vulnerability Exchange Entry Vulnerability database entry
- SOUND4 Product Homepage
- VulnCheck Advisory: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated Remote Code Execution via upload.cgi Third-party advisory