CVE-2025-1050
- EPSS 0.18%
- Veröffentlicht 23.04.2025 16:44:54
- Zuletzt bearbeitet 25.08.2025 14:43:50
Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. ...
CVE-2025-1049
- EPSS 0.16%
- Veröffentlicht 23.04.2025 16:44:33
- Zuletzt bearbeitet 25.08.2025 14:43:00
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerabil...
CVE-2025-1048
- EPSS 0.18%
- Veröffentlicht 23.04.2025 16:44:16
- Zuletzt bearbeitet 25.08.2025 14:40:54
Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to ex...
CVE-2023-50809
- EPSS 2.92%
- Veröffentlicht 12.08.2024 13:38:11
- Zuletzt bearbeitet 13.03.2025 16:15:14
In certain Sonos products before S1 Release 11.12 and S2 release 15.9, the mt_7615.ko wireless driver does not properly validate an information element during negotiation of a WPA2 four-way handshake. This lack of validation leads to a stack buffer o...
CVE-2023-27352
- EPSS 0.07%
- Veröffentlicht 20.04.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:52:43
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of ...
CVE-2023-27353
- EPSS 0.07%
- Veröffentlicht 20.04.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:52:43
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the msprox...
CVE-2023-27354
- EPSS 0.12%
- Veröffentlicht 20.04.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:52:43
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the proces...
CVE-2023-27355
- EPSS 0.07%
- Veröffentlicht 20.04.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:52:43
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw exists within the MPEG-TS parser...
CVE-2022-24046
- EPSS 7.42%
- Veröffentlicht 18.02.2022 20:15:17
- Zuletzt bearbeitet 21.11.2024 06:49:43
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerab...
- EPSS 37.96%
- Veröffentlicht 18.02.2022 20:15:17
- Zuletzt bearbeitet 21.11.2024 06:49:43
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to exploit this vulnerability. The...