Skip to main content

Vendor archive

sonos CVEs

Beta · best-effort

17 CVEs tagged to vendor sonos3 Critical, 9 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-4149

Published Apr 11, 2026

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1051

Published Jun 2, 2025

Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1050

Published Apr 23, 2025

Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 spe…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1049

Published Apr 23, 2025

Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-1048

Published Apr 23, 2025

Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected instal…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-5269

Published Jun 6, 2024

Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5268

Published Jun 6, 2024

Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-5267

Published Jun 6, 2024

Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affe…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-5256

Published Jun 6, 2024

Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9285

Published Oct 20, 2022

Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the m…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-24049

Published Feb 18, 2022

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 syst…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2022-24046

Published Feb 18, 2022

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 5792329…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11316

Published Jul 3, 2018

The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and ne…

CVSS 9.6 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-17 of 17 CVEsPage 1 of 1