Skip to main content
  • 选购
  • 音响
  • 学习
  • 支持
  • 专业

Security Advisory: 2025-0002

Advisory ID: SSA-2025-0002
Severity: High
Issue Date: 2025-08-25
CVE(s): None

Synopsis: Recent software updates include security enhancements that address potential vulnerabilities in networking protocol used by certain third-party integrations.

1. Impacted Products

  • All S1 and S2 Sonos Speakers with at least one authenticated (i.e., login-based, not anonymous) music service provider (MSP) integration.
  • Affected versions: All releases prior to Sonos Systems release v17.1.1 (build 85.0-66270) and Sonos S1 System release v11.15.3 (build 57.22-65130)

2. Introduction
A potential vulnerability was identified in Sonos speakers that could allow an unauthorized user on the same Local Area Network (LAN) to access third-party music service tokens.

3. Third-Party Access Token Vulnerability
Known Attack Vectors: Malicious actors with access to the same Local Area Network as the Sonos speakers can subscribe to UPnP events of a speaker to obtain third-party access tokens. This issue is limited in scope and does not affect users unless a malicious actor gains access to their local network environment.

4. Recommended Mitigations
Resolution:

  • For Sonos S2 System:

Users are advised to disable “UPnP” in your Sonos App settings. Doing this may impact third party control applications that use the UPnP protocol such as SonoPhone or QQMusic.

This guide explains how to disable "Legacy Integrations" on your Sonos system.

  • Open the Sonos app on your device.
  • Go to Account, and select Privacy & Security.
  • Find the UPnP setting and set it to Off.
  • For Sonos S1 System:

S1 was built on an old architecture that relies on the legacy UPnP protocol, which means this issue cannot be resolved via software update. Users are encouraged to implement the workaround outlined below to mitigate risk.

Workaround:

To reduce potential risk on S1 systems, users should ensure that only trusted individuals and devices have access to their local Wi-Fi network. Exploitation of the issue requires a device to be connected to the same LAN as the speaker system.

不错过任何一个节拍或优惠

订阅即可获取有关新产品的最新动态和专属优惠。

您同意接收来自Sonos的动态、促销优惠和其他消息。您可以随时退订。有关更多信息,请查阅我们的《 Privacy Statement》。

帮助

  • 客户
  • 联系我们
  • Sonos社区

帮助

优惠

  • 清仓
  • Sonos测试版

优惠

Sonos简介

  • 我们的公司
  • 新闻
  • 媒体工具包
  • 招贤纳士
  • 投资者
  • 可持续发展和影响力
  • 创始故事
  • Sonos App

Sonos简介

面向企业

  • 安装解决方案
  • 开发者门户
  • Works with Sonos

面向企业

类别

  • 耳机
  • 音响
  • 便携式音响
  • 家庭影院
  • 条形音响
  • 建筑
  • 音频组件
  • 配件

类别

产品

  • Sonos Ace
  • Arc
  • Beam(第2代)
  • Ray
  • Era 100
  • Era 300
  • Roam SL
  • Move 2
  • Sub(第3代)
  • Sub Mini
  • Five
  • Amp
  • Port

产品

© 2026 Sonos, Inc.
  • 法律信息
  • 隐私声明
  • 无障碍服务
  • 符合性
  • 网站地图
  • 安全性