CVE-2026-4149 is a critical remote code execution vulnerability affecting Sonos Era 300 devices, stemming from improper validation of the DataOffset field in SMB responses that permits out-of-bounds memory access. The flaw enables unauthenticated attackers to execute arbitrary code with kernel-level privileges without any user interaction required. The vulnerability presents severe risk with a CVSS score of 9.8 (Critical), characterized by network-based attack vector, low complexity, and no authentication requirement. Exploitation results in complete system compromise with high impact to confidentiality, integrity, and availability of affected devices. Currently, the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation. The EPSS score of 0.0122 indicates relatively low probability of near-term exploitation compared to the broader CVE population, and community attention appears limited given its inactive hot list status. However, the critical severity profile and unauthenticated attack surface warrant prompt patching of affected Sonos Era 300 installations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 83.1-61240CPE matchmatch criteria | cpe:2.3:o:sonos:era_300_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.