CVE-2023-53961

MEDIUM
Published Dec 22, 2025 Modified Jan 16, 2026 CWE-352

Description

SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page.

CVSS v3.1 Score

4.3
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Weakness Type (CWE)

CWE-352 Cross-Site Request Forgery

Affected Products

Vendor Product
sound4 impact_firmware
sound4 impact
sound4 impact_firmware
sound4 impact
sound4 pulse_firmware
sound4 pulse
sound4 pulse_firmware
sound4 pulse
sound4 first_firmware
sound4 first
sound4 first_firmware
sound4 first
sound4 impact_eco_firmware
sound4 impact_eco
sound4 pulse_eco_firmware
sound4 pulse_eco
sound4 big_voice4_firmware
sound4 big_voice4
sound4 big_voice2_firmware
sound4 big_voice2
sound4 wm2_firmware
sound4 wm2
sound4 stream_extension

References

Frequently Asked Questions

What is CVE-2023-53961? +
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. Attackers can craft malicious web pages that submit HTTP requests to the radio processing interface, triggering unintended administrative operations when a logged-in user visits the page. It has a CVSS v3.1 base score of 4.3 (MEDIUM).
How severe is CVE-2023-53961? +
CVE-2023-53961 has a CVSS v3.1 score of 4.3 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2023-53961? +
CVE-2023-53961 affects products from sound4, specifically: big_voice2, big_voice2_firmware, big_voice4, big_voice4_firmware, first, first_firmware, impact, impact_eco, impact_eco_firmware, impact_firmware, pulse, pulse_eco, pulse_eco_firmware, pulse_firmware, stream_extension, wm2, wm2_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2023-53961? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2023-53961 — free, no signup required.

Start Free Scan