Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Zero‑Day RCE (CVE‑2026‑4149) in Sonos Era 300 Smart Speaker Threatens Enterprise Networks

A remote, unauthenticated out‑of‑bounds write in the SMB response handling of Sonos Era 300 speakers (CVE‑2026‑4149) enables kernel‑level code execution. The flaw scores 10.0 on CVSS and is actively exploitable, creating a supply‑chain risk for organizations that deploy these devices in corporate environments.

LiveThreat™ Intelligence · 📅 March 17, 2026· 📰 zerodayinitiative.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Zero‑Day RCE (CVE‑2026‑4149) in Sonos Era 300 Smart Speaker Threatens Enterprise Networks

What It Is – A newly disclosed out‑of‑bounds write‑up in the SMB response handling of the Sonos Era 300 smart speaker (CVE‑2026‑4149) permits unauthenticated remote code execution with kernel‑level privileges.

Exploitability – The flaw is actively exploitable; proof‑of‑concept code has been shared with the vendor. CVSS 3.1 base score 10.0 (Critical).

Affected Products – Sonos Era 300 (firmware < 83.1‑61240).

TPRM Impact – Organizations that deploy Sonos speakers in offices, hotels, retail spaces, or conference rooms inherit a direct attack surface into their internal network. A compromised speaker can be leveraged to pivot, exfiltrate data, or disrupt critical services, representing a supply‑chain risk for third‑party risk managers.

Recommended Actions –

  • Verify firmware version on all Sonos Era 300 devices; upgrade immediately to 83.1‑61240 or later.
  • Isolate audio‑system VLANs from core corporate networks; enforce strict firewall rules on SMB ports (445/TCP).
  • Update asset inventories to include consumer‑grade IoT devices and assess their exposure.
  • Incorporate Sonos as a monitored asset in endpoint‑detection‑and‑response (EDR) platforms.
  • Review contracts with facilities‑management vendors to ensure they follow patch‑management best practices for IoT.

Source: Zero Day Initiative Advisory – ZDI‑26‑192

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-192/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →