First

Vendor:

First CVE: Nov 19, 2025 · Active for under a year

22
Total CVEs
More Total CVEs than 94% of tracked products
22.0
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact First over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2025
8 months ago
Most Recent CVE
Dec 30, 2025
206 days ago

CVE Severity & Scoring

First22 CVEs
All CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local4 (18.2%)
Network18 (81.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None21 (95.5%)
Unknown0 (0.0%)
Required1 (4.5%)
Privileges Required
Low5 (22.7%)
High1 (4.5%)
None16 (72.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell commands through the 'pass
Dec 22, 20259.836NONO
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an unauthenticated vulnerability in the /usr/cgi-bin/restorefactory.cgi endpoint that allows remote attackers to reset device configurat
Dec 22, 20259.834NONO
SOUND4 IMPACT/FIRST/PULSE/Eco version 2.x contains an SQL injection vulnerability in the 'index.php' authentication mechanism that allows attackers to manipulate login credentials.
Dec 22, 20259.834NONO
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain an unauthenticated command injection vulnerability in the username parameter. Attackers can exploit index.php and login
Dec 30, 20259.831NONO
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x contains an insecure direct object reference vulnerability that allows attackers to bypass authorization and access hidden system resources. Atta
Dec 22, 20259.831NONO
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an unauthenticated remote code execution vulnerability in the firmware upload functionality with path traversal flaw. Attackers can exp
Dec 30, 20259.830NONO
SOUND4 IMPACT/FIRST/PULSE/Eco versions 2.x and below contain hardcoded credentials embedded in server binaries that cannot be modified through normal device operations. Attackers c
Dec 30, 20259.830NONO
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an SQL injection vulnerability in the 'username' POST parameter of index.php that allows attackers to manipulate database queries. Atta
Dec 30, 20259.830NONO
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains a conditional command injection vulnerability that allows local authenticated users to create malicious files in the /tmp directory. Un
Dec 30, 20257.826NONO
SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x contains an authenticated command injection vulnerability in the www-data-handler.php script that allows attackers to inject system commands thr
Dec 30, 20258.826NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For First

Top CWEs

Versions

No cataloged versions.