CVE-2025-1048 Details
Description
Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SMB data. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the anacapa user. Was ZDI-CAN-25535.
A use-after-free vulnerability allowing remote code execution has been identified in the Sonos Era 300 speaker, specifically within the libsmb2 library. This issue arises from improper validation of object existence before performing operations, particularly in the handling of SMB data. As a result, network-adjacent attackers can execute arbitrary code on the device, with the executed code running under the context of the 'anacapa' user. Notably, no authentication is required to exploit this vulnerability.
Users should update their Sonos Era 300 speakers to version 16.6 or later. For the Sonos S1 app, version 11.15.1 or later is required. Update instructions can be found on the Sonos support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-25-223/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sonos s1 | < 57.22-61162 |
CPE
Remediation
| |
| sonos s2 | < 83.1-61240 |
CPE
Remediation
| |
| sonos era 300 | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 25, 2025 | Initial Analysis | [email protected] |
| Apr 23, 2025 | New CVE Received | [email protected] |