Vulnerability index

Browse CVEs

16 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Era 300 Firmware CRITICAL 9.8
CVE-2026-4149

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary …

Fix: 83.1-61240+
Fix from $2,300 2026-04-11
Era 300 Firmware HIGH 8.8
CVE-2025-1051

Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra…

Mitigation only
Fix from $1,950 2025-06-02
S2 HIGH 8.8
CVE-2025-1050

Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code…

Fix: 83.1-61240+
Fix from $1,950 2025-04-23
S1 HIGH 8.8
CVE-2025-1048

Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arb…

Fix: 57.22-61162 / 83.1-61240+
Fix from $1,950 2025-04-23
S1 HIGH 8.8
CVE-2025-1049

Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitra…

Fix: 57.22-61162 / 83.1-61240+
Fix from $1,950 2025-04-23
Era 100 Firmware HIGH 8.8
CVE-2024-5267

Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to …

Mitigation only
Fix from $1,950 2024-06-06
Era 100 Firmware HIGH 8.8
CVE-2024-5269

Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu…

Mitigation only
Fix from $1,950 2024-06-06
Era 100 Firmware MEDIUM 6.5
CVE-2024-5268

Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to …

Mitigation only
Fix from $1,600 2024-06-06
One Firmware HIGH 8.8
CVE-2023-27352

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authenticat…

Fix: 11.7.1 / 15.1+
Fix from $1,950 2023-04-20
One Firmware HIGH 8.8
CVE-2023-27355

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authenticat…

Fix: 11.7.1 / 15.1+
Fix from $1,950 2023-04-20
One Firmware MEDIUM 6.5
CVE-2023-27353

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Aut…

Fix: 11.7.1 / 15.1+
Fix from $1,600 2023-04-20
One Firmware MEDIUM 6.5
CVE-2023-27354

This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Aut…

Fix: 11.7.1 / 15.1+
Fix from $1,600 2023-04-20
One Firmware MEDIUM 6.8
CVE-2020-9285

Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the …

No fix yet
Fix from $1,600 2022-10-20
S1 CRITICAL 9.8
CVE-2022-24049EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 1…

Fix: 3.4.1 / 11.2.13+
Fix from $2,300 2022-02-18
S1 HIGH 8.8
CVE-2022-24046

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 syst…

Fix: 3.4.1 / 11.2.13+
Fix from $1,950 2022-02-18
Sonos Firmware CRITICAL 9.6
CVE-2018-11316

The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device contro…

Mitigation only
Fix from $2,300 2018-07-03