First
Vendor:
First CVE: Nov 19, 2025 · Active for under a year
22
Total CVEs
More Total CVEs than 94% of tracked products
22.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact First over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2025
8 months ago
Most Recent CVE
Dec 30, 2025
206 days ago
CVE Severity & Scoring
First22 CVEs
59%
36%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (18.2%)
Network18 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (95.5%)
Unknown0 (0.0%)
Required1 (4.5%)
Privileges Required
Low5 (22.7%)
High1 (4.5%)
None16 (72.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-53963CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'pass | Dec 22, 2025 | 9.8 | 36 | NO | NO |
CVE-2023-53964CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configurat | Dec 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2023-53960CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials. | Dec 22, 2025 | 9.8 | 34 | NO | NO |
CVE-2022-50794CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login | Dec 30, 2025 | 9.8 | 31 | NO | NO |
CVE-2023-53955CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Atta | Dec 22, 2025 | 9.8 | 31 | NO | NO |
CVE-2022-50796CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exp | Dec 30, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-50696CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers c | Dec 30, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-50694CRITICAL SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Atta | Dec 30, 2025 | 9.8 | 30 | NO | NO |
CVE-2022-50795HIGH SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Un | Dec 30, 2025 | 7.8 | 26 | NO | NO |
CVE-2022-50793HIGH SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands thr | Dec 30, 2025 | 8.8 | 26 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For First
Top CWEs
Versions
No cataloged versions.