VYPR

First Firmware

by Sound4 Ltd.

CVEs (22)

  • CVE-2025-63220HigNov 19, 2025
    risk 0.47cvss 7.2epss 0.00

    The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and…

  • CVE-2023-53961MedDec 22, 2025
    risk 0.28cvss 4.3epss 0.00

    SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering…

Page 2 of 2