Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sonos

First CVE: Jul 3, 2018Active for: 8 yearsTotal CVEs: 17
35.9
VTI Score
Medium

Sonos maintains a focused product line of networked audio speakers and systems spanning generations from the S1 and S2 platforms through current models such as the Era 300 and One, devices that are widely embedded in consumer and commercial listening environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur through memory-safety weakness classes including out-of-bounds writes and reads, use-after-free conditions, heap buffer overflows, and integer underflow—issues endemic to native firmware implementations handling audio processing and network protocols. Defenders should prioritize inventory and patching of Sonos devices within their network scope, as the vendor's disclosures reflect the attack surface inherent to always-on, internet-connected audio hardware; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
17
Total CVEs
More Total CVEs than 95% of tracked vendors
0.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 2% of tracked vendors
8.2
Avg CVSS Score
Higher Avg CVSS Score than 80% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sonos over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 3, 2018
8 years ago
Most Recent CVE
Apr 11, 2026
104 days ago

Products(10 total)

Top CVEs

Signals from CVEs in this vendor scope (17 CVEs).

17 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-4149CRITICAL
Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations
Apr 11, 20269.834NONO
CVE-2022-24049CRITICAL
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 syste
Feb 18, 20229.832NONO
CVE-2025-1049HIGH
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 3
Apr 23, 20258.828NONO
CVE-2018-11316CRITICAL
The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and net
Jul 3, 20189.628NONO
CVE-2025-1050HIGH
Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 spea
Apr 23, 20258.827NONO
CVE-2023-27355HIGH
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit
Apr 20, 20238.827NONO
CVE-2023-27352HIGH
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit
Apr 20, 20238.827NONO
CVE-2025-1048HIGH
Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected install
Apr 23, 20258.825NONO
CVE-2025-1051HIGH
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 3
Jun 2, 20258.824NONO
CVE-2024-5269HIGH
Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected i
Jun 6, 20248.824NONO
View all 17 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products17 CVEs
29%
53%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network3 (17.6%)
Unknown0 (0.0%)
Physical1 (5.9%)
Adjacent Network13 (76.5%)
Attack Complexity
Low17 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None16 (94.1%)
Unknown0 (0.0%)
Required1 (5.9%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None17 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (17 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sonos.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sonos — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sonos's Products

View all 2 CNAs →

Top CWEs