Junglewise Threat Intelligence

CVE-2026-4149: Sonos Era 300 SMB out-of-bounds access remote code execution

CVE-2026-4149 · Severity: critical · CVSS 9.8 · Published 2026-04-11

Executive brief

The Sonos Era 300 smart speaker is vulnerable to a critical security flaw that allows an attacker to take full control of the device over the network. By sending a specially crafted response during file-sharing communications, an attacker can execute malicious commands without needing any login credentials. This could lead to unauthorized access to the device's functions, potential eavesdropping, or using the speaker as a foothold to attack other devices on the home or corporate network.

Technical details

An out-of-bounds access vulnerability exists in the Sonos Era 300's implementation of the SMB protocol. The flaw is located in the handling of the DataOffset field within SMB responses, where the system fails to properly validate user-supplied data. This lack of validation allows for memory access beyond the end of an allocated buffer. A remote, unauthenticated attacker can exploit this to execute arbitrary code with kernel-level privileges. The vulnerability was addressed in firmware version 83.1-61240.

Affected products

  • Sonos Era 300 Before 83.1-61240

Timeline

  • 2025-11-06: other: Vulnerability reported to vendor
  • 2026-03-16: patched: Coordinated public release of advisory and fix in version 83.1-61240
  • 2026-04-11: advisory: NVD publication date

References