VYPR

XAV-9500ES

by Sony

CVEs (7)

  • CVE-2026-18279HigAug 20, 2026
    risk 0.57cvss 8.8epss

    Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The…

  • CVE-2026-18282HigAug 20, 2026
    risk 0.52cvss 8.0epss

    Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability…

  • CVE-2026-18281HigAug 20, 2026
    risk 0.52cvss 8.0epss

    Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to…

  • CVE-2026-18284HigAug 20, 2026
    risk 0.51cvss 7.8epss

    Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to execute…

  • CVE-2026-18280LowAug 20, 2026
    risk 0.25cvss 3.9epss

    Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The…

  • CVE-2026-18278LowAug 20, 2026
    risk 0.23cvss 3.5epss

    Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to…

  • CVE-2026-18283LowAug 20, 2026
    risk 0.16cvss 2.4epss

    Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific…