索尼 XAV-9500ES 的 udev USB 规则授权绕过漏洞。该漏洞允许物理上能够接触设备的攻击者绕过索尼 XAV-9500ES 设备上受影响系统的授权机制。利用此漏洞无需进行身份认证。 该特定缺陷存在于 udev 规则中。攻击者通过向系统连接一个特制的 USB 设备,即可触发原本受限的 USB 设备类型的实例化。攻击者可借此漏洞绕过系统授权机制。此漏洞此前已由 ZDI-CAN-28992 编号披露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sony | XAV-9500ES | 3.02.00 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sony | XAV-9500ES | 3.02.00 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18280 | Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability | |
| CVE-2026-18279 | Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability | |
| CVE-2026-18281 | Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnera | |
| CVE-2026-18282 | Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution | |
| CVE-2026-18278 | Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerabili | |
| CVE-2026-18284 | Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerabil |
No comments yet