Some versions of Sonos One (1st and 2nd generation) allow partial or full memory access via attacker controlled hardware that can be attached to the Mini-PCI Express slot on the motherboard that hosts the WiFi card on the device.
The chip does not implement or does not correctly perform access control to check whether users are authorized to access internal registers and test modes through the physical debug/test interface.
Link | Tags |
---|---|
https://tnpitsecurity.com/blog/gaining-root-on-sonos-speakers/ | third party advisory exploit |