Skip to main content
  • 製品
  • 学ぶ
  • サポート
  • プロフェッショナル

Security Advisory: 2025-0001

Advisory ID: SSA-2025-0001
Severity: High
Issue Date: 2025-06-10
CVE(s): CVE-2025-24132, CVE-2025-30422

Synopsis: Recent firmware updates address a security vulnerability in AirPlay implementation (CVE-2025-24132, CVE-2025-30422)

1. Impacted Products

  • All Sonos AirPlay-enabled devices.
  • Affected versions: All releases prior to Sonos Systems release v17.1 (build 85.0-65270) and Sonos S1 System release v11.15.3 (build 57.22-65130)

2. Introduction
Multiple vulnerabilities were identified in the AirPlay SDK implementation that affects third-party devices incorporating this technology, including Sonos's AirPlay-enabled products. This update remediates the vulnerability by implementing the patched AirPlay SDK with improved input validation and improved memory handling.

3. AirPlay Stack-Based Buffer Overflow Vulnerability (CVE-2025-24132)
Description: A stack-based buffer overflow vulnerability in the AirPlay implementation could allow an attacker on the local network to execute arbitrary code without user interaction
Known Attack Vectors: Malicious actors on the same local network could send specially crafted AirPlay requests to exploit this zero-click vulnerability
Resolution: To remediate CVE-2025-24132, apply the Sonos Systems release v17.1 (build 85.0-65270) and Sonos S1 System release v11.15.3 (build 57.22-65130) or later, which implements the patched AirPlay Audio SDK

4. AirPlay Authentication Bypass Vulnerability (CVE-2025-30422)
Description: A vulnerability in the authentication mechanism could allow an attacker to bypass authentication controls and gain unauthorized access to the device
Known Attack Vectors: Malicious actors on the same local network could send specially crafted authentication requests that bypass validation checks
Resolution: To remediate CVE-2025-30422, apply the Sonos Systems release v17.1 (build 85.0-65270) and Sonos S1 System release v11.15.3 (build 57.22-65130) or later, which implements the patched AirPlay Audio SDK
Additional Documentation: Apple Security Advisory: https://support.apple.com/en-us/122403
Acknowledgments: Sonos would like to thank the Oligo Security Research Team for their responsible disclosure of this vulnerability.


Trademark Attributions: Apple, AirPlay and other Apple marks are trademarks of Apple Inc., registered in the U.S. and other countries and regions. All third-party trademarks references in this document are property of their respective owners. Use of the does not imply affiliation with or endorsement by those entities.

最新情報をお届け

登録すると、新製品や限定オファーなどの最新情報をお知らせします。

お客様は、Sonosから最新情報やプロモーションなどのお知らせを受け取ることに同意されたものとみなされます。詳細は、 Privacy Statement をご覧ください。

サポート

  • アカウント
  • 店舗検索
  • お問い合わせ
  • Sonosコミュニティ

サポート

セール

  • ラストチャンス
  • Sonosベータ版

セール

Sonosについて

  • Sonosについて
  • ニュース
  • メディアキット
  • 採用情報
  • 投資家向け情報 (English Only)
  • サステナビリティ&環境への影響 (English Only)
  • Sonos創業ストーリー
  • ブログ
  • Sonosアプリ

Sonosについて

法人向け

  • 設置業者向け
  • 開発者向けポータル
  • トレード
  • Works with Sonos

法人向け

カテゴリー

  • ヘッドフォン
  • スピーカー
  • ポータブルスピーカー
  • ホームシアター
  • サウンドバー
  • コンポーネント
  • アクセサリー

カテゴリー

製品

  • Sonos Play
  • Sonos Ace
  • Sonos Arc Ultra
  • Sonos Beam (Gen 2)
  • Sonos Ray
  • Sonos Era 100
  • Sonos Era 100 SL
  • Sonos Era 300
  • Sonos Roam 2
  • Sonos Move
  • Sonos Sub 4
  • Sonos Sub Mini
  • Sonos Five
  • Sonos Amp
  • Sonos Port

製品

© 2026 Sonos, Inc.
  • 法的情報
  • プライバシーに関する声明
  • アクセシビリティ
  • 適合宣言書
  • サイトマップ
  • セキュリティ