关键信息 漏洞名称: SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Unauthenticated File Disclosure Vulnerability 严重性: High 日期: December 30, 2025 CVE标识: CVE-2022-50792 CVE评级: 8.7 CVSS V4 Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CWE编号: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 描述: SOUND4 IMPACT/FIRST/PULSE/Eco 版本2.x及以下版本包含一个未授权文件披露漏洞,可以让远程攻击者访问敏感系统文件。攻击者可以通过操纵'file' GET参数来披露受影响设备上的任意文件。 受影响版本: - Impact/Pulse/First Version 2: 1.1/2.15 - Impact/Pulse Eco 1.16 - BigVoice4 1.2 - BigVoice2 1.30 - LiveStream 1.1/2.4.29 - LBX2 1.11 参考资料: - Zero Science Lab Disclosure (ZSL-2022-5736) - Packet Storm Security Exploit Details - IBM X-Force Vulnerability Exchange Entry - SOUND4 Product Homepage 贡献者: LiquidWorm as Gjoko Krstic of Zero Science Lab