Skip to content
Noroxi

Sonos records

19 published records for vendor sonos.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
15
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 18
  2. 22
  3. 23
  4. 24
  5. 25
  6. 26

Bar: total · dark part: CISA KEV.

All records

19 records
  • This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 syste

    CriticalCVSS 9.8No exploitEPSS 7%

    sonos · s1Feb 18, 2022

  • CVE-2026-4149
    39Monitor

    Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability

    CriticalCVSS 9.8No exploitEPSS 1%

    sonos · era 300 firmwareApr 10, 2026

  • The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack.

    CriticalCVSS 9.6No exploitEPSS 1%

    sonos · sonos firmwareJul 3, 2018

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1

    HighCVSS 8.8No exploitEPSS 4%

    sonos · s1Feb 18, 2022

  • CVE-2024-5269
    35Monitor

    Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    sonos · era 100 firmwareJun 6, 2024

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220.

    HighCVSS 8.8No exploitEPSS 1%

    sonos · one firmwareApr 20, 2023

  • This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220.

    HighCVSS 8.8No exploitEPSS 1%

    sonos · one firmwareApr 20, 2023

  • CVE-2024-5267
    35Monitor

    Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    sonos · era 100 firmwareJun 6, 2024

  • CVE-2025-1048
    35Monitor

    Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 1%

    sonos · s1Apr 23, 2025

  • CVE-2025-1050
    35Monitor

    Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    sonos · s2Apr 23, 2025

  • CVE-2025-1049
    35Monitor

    Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    sonos · s1Apr 23, 2025

  • CVE-2025-1051
    35Monitor

    Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability

    HighCVSS 8.8No exploitEPSS 0%

    sonos · era 300 firmwareJun 2, 2025

  • In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an informat

    HighCVSS 7.8No exploitEPSS 0%

    Aug 12, 2024

  • CVE-2020-9285
    27Monitor

    Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attache

    MediumCVSS 6.8No exploitEPSS 0%

    sonos · one firmwareOct 20, 2022

  • This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3

    MediumCVSS 6.5No exploitEPSS 1%

    sonos · one firmwareApr 20, 2023

  • This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3

    MediumCVSS 6.5No exploitEPSS 1%

    sonos · one firmwareApr 20, 2023

  • CVE-2024-5268
    26Monitor

    Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability

    MediumCVSS 6.5No exploitEPSS 0%

    sonos · era 100 firmwareJun 6, 2024

  • In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware

    MediumCVSS 6.0No exploitEPSS 1%

    Aug 12, 2024

  • CVE-2024-5256
    17Monitor

    Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability

    MediumCVSS 4.3No exploitEPSS 0%

    sonos · era 100 firmwareJun 6, 2024