CVE-2025-57431

8.8

Sound4 · PULSE-ECO AES67

The Sound4 PULSE-ECO AES67 web interface allows unauthenticated remote code execution via a maliciously crafted, unvalidated firmware update package.

Executive summary

A critical remote code execution vulnerability in the Sound4 PULSE-ECO AES67 firmware update mechanism poses a severe risk of full system compromise.

Vulnerability

The web-based management interface fails to validate the integrity of the manual.sh script within firmware update packages, allowing unauthenticated attackers to execute arbitrary commands by repackaging the firmware.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve complete control over the affected hardware device. This level of access can lead to unauthorized data interception, permanent denial of service, or the use of the device as a persistent foothold within the internal network. Given the CVSS score of 8.8, this flaw represents a high-risk entry point that could significantly impact operational continuity and network security.

Remediation

Immediate Action: Restrict access to the web-based management interface of all Sound4 PULSE-ECO AES67 units to trusted management networks only, and avoid performing manual firmware updates until a vendor-supplied patch is available.

Proactive Monitoring: Monitor network traffic for unusual outbound connections or unexpected file modifications originating from the management interface.

Compensating Controls: Deploy a Web Application Firewall (WAF) or network access control list (ACL) to block unauthorized access to the web management console of the device.

Exploitation status

Public Exploit Available: Yes, a published PoC exists, attributed to the researcher's write-up referenced in the CVE record.

Analyst recommendation

This vulnerability is severe and requires immediate attention to prevent potential exploitation. Because the update mechanism itself is compromised, administrators must prioritize network isolation of the affected devices and maintain strict access controls until Sound4 releases an official firmware update that addresses the integrity validation failure.

Sources