CVE-2025-1050
CVSS 3.0 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-1050 is a remote code execution vulnerability affecting Sonos Era 300 speakers. Network-adjacent attackers can exploit this issue without requiring authentication. The root cause of the vulnerability is the lack of proper validation of user-supplied data, which leads to an out-of-bounds write condition. An attacker can manipulate HLS playlist data to write past the allocated data structure, resulting in arbitrary code execution in the context of the anacapa user. This vulnerability, identified as ZDI-CAN-25606, poses a significant risk to affected devices.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.