Vulnerability record · CVE-2023-53964 · published 22 December 2025
CVE-2023-53964: Sound4 impact firmware missing authentication for critical function vulnerability
Sound4 · Impact Firmware
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.
Description
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configuration. Attackers can send a POST request to the endpoint with specific data to trigger a factory reset and bypass authentication, gaining full system control.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Affected products
9 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://web.archive.org/web/20221207074555/https://www.sound4.com/ | Product |
| https://www.exploit-db.com/exploits/51174 | ExploitThird Party AdvisoryVDB Entry |
| https://www.vulncheck.com/advisories/sound-impactfirstpulseeco-x-unauthenticated-factory-reset-vulnerability | Third Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5742.php | ExploitThird Party Advisory |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2022-5742.php | ExploitThird Party Advisory |
Track CVE-2023-53964 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-53964), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.