CVE-2026-4149Disclosure(sonos / era_300)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the DataOffset field within SMB responses. The issue results from the lack of proper validation of user-supplied data, which can result in a memory access past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the kernel. Was ZDI-CAN-28345.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • era_300
  • era_300_firmware

Threat summary

  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-04-11)
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
era_300era_300_firmware

1 version affected across 2 products

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-03-16: 1Mentions · 2026-03-18: 1Mentions · 2026-04-11: 3Technical Details · 2026-03-16: 1Technical Details · 2026-04-11: 303-1603-1804-11
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-161
Disclosure1
2026-03-181
General1
2026-04-113
Disclosure3
Full discourse5 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-192|CVE-2026-4149] Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability (CVSS 10.0; Credit: dmdung (@_piers2) of STAR Labs SG Pte. Ltd) https://www.zerodayinitiative.com/advisories/ZDI-26-192/

    Post summary

    The advisory announces CVE‑2026‑4149, a SMB response OOB access and RCE vulnerability in Sonos Era 300, providing a CVSS score and credit but no patch or exploit details.

    0402294.7K
    5.4K followersView on X
  • CTIWatch@ctiwatchcloud
    Disclosure

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-40175 | CVSS 10.0 🔴 CVE-2026-4149 | CVSS 10.0 🔴 CVE-2026-5412 | CVSS 9.9 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The post enumerates three newly identified high‑severity CVEs with their CVSS scores and provides a link to a website, but offers no PoC, exploit code, or patch information.

    00001422
    5.6K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-3342 2 - CVE-2026-4149 3 - CVE-2026-32635 4 - CVE-2025-41237 5 - CVE-2019-17571 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post simply enumerates trending CVE identifiers without offering any technical, exploit, or mitigation information.

    00010169
    1.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4149: CRITICAL] Critical remote code execution vulnerability (ZDI-CAN-28345) discovered in Sonos Era 300. Attackers can exploit SMB responses to execute arbitrary code without authentication.#cve,CVE-2026-4149,#cybersecurity https://cvefind.com/CVE-2026-4149

    Post summary

    The tweet announces a critical remote code execution vulnerability (CVE‑2026‑4149) in Sonos Era 300, detailing how attackers can exploit SMB responses without authentication.

    0000077
    619 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-4149: Sonos Era 300 SMB Response Out-Of... Kernel-level RCE on premium speakers via malformed SMB DataOffset - no auth needed, perfect CVSS 10.0 makes every Era 30... https://zerodaysignal.com/vulnerability/CVE-2026-4149 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces a newly disclosed Sonos Era 300 vulnerability (CVE‑2026‑4149) that permits unauthenticated kernel‑level remote code execution via a malformed SMB DataOffset, rated with a perfect CVSS 10.0 score.

    00000119
    204 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWsonosera_300---
OSsonosera_300_firmware---

Explore more