CVE-2018-11316: Sonos Firmware

Critical severity, CVSS 9.6. EPSS: 1.3% chance of exploitation in the next 30 days.

The UPnP HTTP server on Sonos wireless speaker products allow unauthorized access via a DNS rebinding attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.

Affected products

  • Sonos Sonos Firmware: affected versions not specified

Published 2018-07-03. Last modified 2026-06-17.