CVE-2022-50788

HIGH
Published Dec 30, 2025 Modified Jan 13, 2026 CWE-548

Description

SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication.

CVSS v3.1 Score

7.5
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weakness Type (CWE)

CWE-548 CWE-548

Affected Products

Vendor Product
sound4 first_firmware
sound4 first
sound4 first_firmware
sound4 first
sound4 impact_eco_firmware
sound4 impact_eco
sound4 pulse_eco_firmware
sound4 pulse_eco
sound4 big_voice4_firmware
sound4 big_voice4
sound4 big_voice2_firmware
sound4 big_voice2
sound4 wm2_firmware
sound4 wm2
sound4 impact_firmware
sound4 impact
sound4 impact_firmware
sound4 impact
sound4 pulse_firmware
sound4 pulse
sound4 pulse_firmware
sound4 pulse
sound4 stream_extension

References

Frequently Asked Questions

What is CVE-2022-50788? +
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an information disclosure vulnerability that allows unauthenticated attackers to access sensitive log files. Attackers can directly browse the /log directory to retrieve system and sensitive information without authentication. It has a CVSS v3.1 base score of 7.5 (HIGH).
How severe is CVE-2022-50788? +
CVE-2022-50788 has a CVSS v3.1 score of 7.5 out of 10, rated HIGH. This is a high-severity vulnerability that should be prioritized for patching.
What products are affected by CVE-2022-50788? +
CVE-2022-50788 affects products from sound4, specifically: big_voice2, big_voice2_firmware, big_voice4, big_voice4_firmware, first, first_firmware, impact, impact_eco, impact_eco_firmware, impact_firmware, pulse, pulse_eco, pulse_eco_firmware, pulse_firmware, stream_extension, wm2, wm2_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2022-50788? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2022-50788 — free, no signup required.

Start Free Scan