Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability
Description
Sonos Era 100 contains an out-of-bounds read in SMB2 message handling that can leak memory and lead to root-level code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Sonos Era 100 contains an out-of-bounds read in SMB2 message handling that can leak memory and lead to root-level code execution.
Vulnerability
An out-of-bounds read vulnerability exists in the handling of SMB2 messages on the Sonos Era 100 smart speaker ([1]). The issue stems from insufficient validation of user-supplied data, allowing a read past the end of an allocated buffer. This affects all versions of the Sonos Era 100 firmware prior to the fix included in the June 2024 update.
Exploitation
An attacker can exploit this vulnerability from a network-adjacent position without requiring any authentication. The attack involves sending a specially crafted SMB2 message to the vulnerable device, triggering the out-of-bounds read. While the direct impact is a limited information disclosure, the ZDI advisory notes that this can be chained with other vulnerabilities to achieve full code execution ([1]).
Impact
Successful exploitation allows an attacker to read sensitive memory contents from the device, potentially leaking cryptographic keys, configuration data, or other secrets. More critically, an attacker can use this vulnerability as a stepping stone in a chain of exploits to execute arbitrary code in the context of the root user, gaining full control of the device ([1]).
Mitigation
Sonos released a firmware update in June 2024 that resolves this vulnerability. Users should ensure their Era 100 devices are updated to the latest firmware version. No public workaround is available. The vulnerability is not currently listed on the CISA KEV, but active exploitation as part of the Pwn2Own contest was demonstrated ([1]).
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Sonos/Era 100v5Range: 15.9 (build 75146030)
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
1- www.zerodayinitiative.com/advisories/ZDI-24-544/mitrex_research-advisory
News mentions
0No linked articles in our index yet.