ZDI-CAN-25535: ZDI-25-223: (Pwn2Own) Sonos Era 300 Speaker libsmb2 Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of SMB data. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the anacapa user.
Other sources
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 300 speakers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2025-1048.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25535?
The severity of ZDI-CAN-25535 is rated at 8.8 on the CVSS scale.
What vulnerability allows network-adjacent attackers to execute arbitrary code in Sonos Era 300 speakers?
ZDI-CAN-25535 allows network-adjacent attackers to execute arbitrary code on affected installations.
Is authentication required to exploit ZDI-CAN-25535?
No, authentication is not required to exploit ZDI-CAN-25535.
What is the CVE associated with ZDI-CAN-25535?
The CVE assigned to ZDI-CAN-25535 is CVE-2025-1048.
Which product is affected by ZDI-CAN-25535?
The affected product is the Sonos Era 300.