« Back to list

Sonos

Sonos S2: vulnerabilities and CVEs

Sonos S2 has 9 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.

CVEs9
Last 12 months0
Critical1
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-1050High (8.8)0.42%—Apr 23, 2025
Sonos Era 300 Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to…
CVE-2025-1049High (8.8)0.42%—Apr 23, 2025
Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not…
CVE-2025-1048High (8.8)0.54%—Apr 23, 2025
Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers.…
CVE-2023-27355High (8.8)0.81%—Apr 20, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw…
CVE-2023-27354Medium (6.5)0.63%—Apr 20, 2023
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The…
CVE-2023-27353Medium (6.5)0.63%—Apr 20, 2023
This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The…
CVE-2023-27352High (8.8)0.78%—Apr 20, 2023
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker 70.3-35220. Authentication is not required to exploit this vulnerability. The specific flaw…
CVE-2022-24049Critical (9.8)7.2%—Feb 18, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not required to…
CVE-2022-24046High (8.8)4.1%—Feb 18, 2022
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos One Speaker prior to 3.4.1 (S2 systems) and 11.2.13 build 57923290 (S1 systems). Authentication is not…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059 Command and Scripting Interpreter3
  2. T1210 Exploitation of Remote Services3

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Sonos