CVE-2026-18279 ‒ Sony XAV-9500ES Buffer Overflow Remote Code Execution Vulnerability (Pwn2Own)

Authored by:
Metrics: cve.org

Description

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.

Vulnerability

The specific flaw exists within the handling of SETUP RTSP packets. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An unauthenticated attacker can leverage this vulnerability to execute code arbitrary code on the device.

Mitigations

Update to Version 3.04.00 or later.

Timeline

DateAction
22.01.2026Vulnerability demonstrated and disclosed to ZDI at Pwn2Own Automotive
19.03.2026Vulnerability reported to vendor
16.07.2026Update published by vendor
29.07.2026Coordinated public release of advisory

References

Share: