S2
Sonos · 10 CVEs
Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability
Apr 23, 2025
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability
Apr 23, 2025
Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability
Apr 23, 2025
In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly…
Aug 9, 2024
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One S…
Apr 20, 2023
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Son…
Apr 20, 2023
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Son…
Apr 20, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One S…
Apr 20, 2023
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker pri…
Feb 18, 2022
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One S…
Feb 18, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-1050 | Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability | HIGH | 0.42% | Apr 23, 2025 |
| CVE-2025-1049 | Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability | HIGH | 0.42% | Apr 23, 2025 |
| CVE-2025-1048 | Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability | HIGH | 0.54% | Apr 23, 2025 |
| CVE-2023-50809 | In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during… | HIGH | 0.39% | Aug 9, 2024 |
| CVE-2023-27355 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not… | HIGH | 0.81% | Apr 20, 2023 |
| CVE-2023-27354 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authenticatio… | MEDIUM | 0.63% | Apr 20, 2023 |
| CVE-2023-27353 | This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authenticatio… | MEDIUM | 0.63% | Apr 20, 2023 |
| CVE-2023-27352 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not… | HIGH | 0.78% | Apr 20, 2023 |
| CVE-2022-24049 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 bui… | CRITICAL | 7.21% | Feb 18, 2022 |
| CVE-2022-24046 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 1… | HIGH | 4.08% | Feb 18, 2022 |
Showing 1 to 10 of 10 CVEs