Sonos maintains a focused product line of networked audio speakers and systems spanning generations from the S1 and S2 platforms through current models such as the Era 300 and One, devices that are widely embedded in consumer and commercial listening environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety weakness classes including out-of-bounds writes and reads, use-after-free conditions, heap buffer overflows, and integer underflow—issues endemic to native firmware implementations handling audio processing and network protocols. Defenders should prioritize inventory and patching of Sonos devices within their network scope, as the vendor's disclosures reflect the attack surface inherent to always-on, internet-connected audio hardware; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sonos over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4149CRITICAL Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations | Apr 11, 2026 | 9.8 | 34 | NO | NO |
CVE-2022-24049CRITICAL This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 syste | Feb 18, 2022 | 9.8 | 32 | NO | NO |
CVE-2025-1049HIGH Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 3 | Apr 23, 2025 | 8.8 | 28 | NO | NO |
CVE-2018-11316CRITICAL The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and net | Jul 3, 2018 | 9.6 | 28 | NO | NO |
CVE-2025-1050HIGH Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 spea | Apr 23, 2025 | 8.8 | 27 | NO | NO |
CVE-2023-27355HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit | Apr 20, 2023 | 8.8 | 27 | NO | NO |
CVE-2023-27352HIGH This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit | Apr 20, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-1048HIGH Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected install | Apr 23, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-1051HIGH Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 3 | Jun 2, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-5269HIGH Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected i | Jun 6, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sonos.
Media articles that mention a CVE ID that affects a product developed by Sonos — matched by CVE ID, not by vendor name.