ZDI-25-311: (Pwn2Own) Sonos Era 300 Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of ALAC data. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the anacapa user.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-1051.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-311?
The severity of ZDI-25-311 is rated as 8.8 on the CVSS scale.
How does ZDI-25-311 affect Sonos Era 300 speakers?
ZDI-25-311 allows network-adjacent attackers to execute arbitrary code on affected Sonos Era 300 speakers.
Is authentication required to exploit ZDI-25-311?
No, authentication is not required to exploit the ZDI-25-311 vulnerability.
What kind of attackers can exploit ZDI-25-311?
Network-adjacent attackers can exploit the ZDI-25-311 vulnerability.
What CVE is associated with ZDI-25-311?
The CVE associated with ZDI-25-311 is CVE-2025-1051.