CVE-2025-1050

CVSS 3.0 Score 8.8 of 10 (high)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 787

Summary

CVE-2025-1050 is a remote code execution vulnerability affecting Sonos Era 300 speakers. Network-adjacent attackers can exploit this issue without requiring authentication. The root cause of the vulnerability is the lack of proper validation of user-supplied data, which leads to an out-of-bounds write condition. An attacker can manipulate HLS playlist data to write past the allocated data structure, resulting in arbitrary code execution in the context of the anacapa user. This vulnerability, identified as ZDI-CAN-25606, poses a significant risk to affected devices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share