Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-63220

The Sound4 FIRST web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware update package. The update mechanism fails to validate the integrity of manual.sh, allowing an attacker to inject arbitrary commands by modifying this script and repackaging the firmware.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 39.9%
CVSS Severity
CVSS v3 Score 7.2
Products affected by CVE-2025-63220


Contact Us

Shodan ® - All rights reserved