216.73.217.22

CVE-2025-57431

· Published 22/09/2025 17:16 · Modified 22/09/2025 21:22

Labels: CVE-2025-57431 2025-09-22CVE-2025-57431CWE-494[email protected]

Essential information

Published
22/09/2025 17:16
Modified
22/09/2025 21:22
Author
Creator
CVSS
8.8 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVSS metrics

Description

The Sound4 PULSE-ECO AES67 1.22 web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
sound4 / pulse-eco cpe:2.3:a:sound4:pulse-eco:*:*:*:*:*:*:*:*

References