CVE-2025-43916
CVSS 3.1 Score 3.4 of 10 (low)
Details
Published Apr 21, 2025
CWE ID 647
Summary
CVE-2025-43916 is a vulnerability affecting Sonos' api.sonos.com up until April 21, 2025. During this period, the /login/v3/oauth endpoint accepted redirect URIs with userinfo in the authority component, which contradicts RFC 6819 guidelines. This issue enabled attackers to potentially receive authorization codes intended for other destinations. Additionally, decompiling the Sonos app uncovered a hardcoded secret, which could exacerbate the consequences of this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Sonos