Skip to main content

Era 300 speaker hacked

  • October 24, 2024
  • 1 reply
  • 219 views

Forum|alt.badge.img

So… the Era 300 was breached today.

https://www.bleepingcomputer.com/news/security/samsung-galaxy-s24-and-sonos-era-hacked-on-pwn2own-ireland-day-2/

“Dungdm from Viettel Cyber Security took control of a Sonos Era 300 smart speaker using a Use-After-Free (UAF) vulnerability. His successful exploit added $30,000 to his team's earnings”

I have been searching but have not seen any response to this yet. Has anyone heard anything?

This topic has been closed for further comments. You can use the search bar to find a similar topic, or create a new one by clicking Create Topic at the top of the page.

1 reply

Stanley_4
  • Lead Maestro
  • October 25, 2024

Sounds like sloppy coding and poor QC testing.

https://www.bleepingcomputer.com/news/security/hackers-exploit-52-zero-days-on-the-first-day-of-pwn2own-ireland/

 

RET2 Systems' Jack Dates followed with a successful out-of-bounds (OOB) write exploit on the Sonos Era 300 smart speaker, securing $60,000 and 6 points. His exploit allowed full control over the device.

 

More details will likely be coming as they did for this previous era100 exploit that was far more difficult.

https://www.nccgroup.com/us/research-blog/shooting-yourself-in-the-flags-jailbreaking-the-sonos-era-100/