Bose's vulnerability disclosures center on its SoundTouch audio and smart-speaker product line, which combines wireless connectivity and web-based control interfaces. The identified exposure recurs through input-handling issues such as cross-site scripting, reflecting the attack surface inherent to networked consumer audio devices with embedded web management. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bose over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17751HIGH Bose SoundTouch devices allows remote attackers to achieve remote control via a crafted web site that uses the WebSocket Protocol. | Mar 24, 2018 | 8.8 | 26 | NO | NO |
CVE-2017-6520CRITICAL The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote atta | May 1, 2017 | 9.1 | 23 | NO | NO |
CVE-2018-12638MEDIUM An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the r | Mar 21, 2019 | 6.1 | 21 | NO | NO |
CVE-2017-17750MEDIUM Bose SoundTouch devices allow XSS via a crafted public playlist from Spotify. | Mar 24, 2018 | 5.4 | 19 | NO | NO |
CVE-2017-17749MEDIUM Bose SoundTouch devices allow XSS via crafted song data from a music service, as demonstrated by Pandora. | Mar 24, 2018 | 5.4 | 19 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bose.
Media articles that mention a CVE ID that affects a product developed by Bose — matched by CVE ID, not by vendor name.