Remote Code Execution Vulnerability in Sonos One Speaker by Sonos
CVE-2023-27352
What is CVE-2023-27352?
The vulnerability in the Sonos One Speaker permits network-adjacent attackers to execute arbitrary code without authentication. This flaw lies in the processing of the SMB directory query command, where the absence of validation for object existence allows attackers to manipulate operations on unverified objects. Exploiting this weakness can enable an attacker to run malicious code with root privileges, posing significant risks to the device’s security and data integrity. For more technical details, refer to the advisory documentation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
One Speaker 70.3-35220
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
