Vulnerabilidades en Sonos
16 resultadosAnálisis Vexday
Sonos registra 16 vulnerabilidades catalogadas, 3 delas críticas, sem nenhuma sob exploração ativa no momento. A fraqueza predominante é CWE-416 (use-after-free), típica de problemas de gerenciamento de memória que podem impactar a disponibilidade e integridade dos dispositivos. Não há vulnerabilidades publicadas nos últimos 90 dias, indicando que o risco atual é estável e sem tendência de novos problemas recentes.
CVE-2022-24049CRITICALThis vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systeEPSS 7.2%CVE-2022-24046CRITICALThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1EPSS 4.1%CVE-2024-5269HIGHSonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution VulnerabilityEPSS 1.2%CVE-2026-4149CRITICALSonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution VulnerabilityEPSS 1.0%CVE-2023-27355HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. AuEPSS 0.8%CVE-2023-27352HIGHThis vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. AuEPSS 0.8%CVE-2024-5267HIGHSonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.7%CVE-2023-27354MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3EPSS 0.6%CVE-2023-27353MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-3EPSS 0.6%CVE-2025-1048HIGHSonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution VulnerabilityEPSS 0.5%CVE-2024-5268MEDIUMSonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-5256MEDIUMSonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-1050HIGHSonos Era 300 Out-of-Bounds Write Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-1049HIGHSonos Era 300 Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.4%CVE-2025-1051HIGHSonos Era 300 Heap-based Buffer Overflow Remote Code Execution VulnerabilityEPSS 0.3%CVE-2025-43916LOWSonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authoriEPSS 0.2%