Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-18283— Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability

Quick assessment

Affected
Sony XAV-9500ES
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

索尼 XAV-9500ES 的 udev USB 规则授权绕过漏洞。该漏洞允许物理上能够接触设备的攻击者绕过索尼 XAV-9500ES 设备上受影响系统的授权机制。利用此漏洞无需进行身份认证。 该特定缺陷存在于 udev 规则中。攻击者通过向系统连接一个特制的 USB 设备,即可触发原本受限的 USB 设备类型的实例化。攻击者可借此漏洞绕过系统授权机制。此漏洞此前已由 ZDI-CAN-28992 编号披露。

AI Predicted 4.4 Difficulty: Moderate EPSS 0.31% · P24

Affected Version Matrix 1

VendorProduct Version RangeStatus
Sony XAV-9500ES 3.02.00 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18283

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Sony XAV-9500ES 3.02.00 -

II. Public POCs for CVE-2026-18283

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-18283

登录查看更多情报信息。

Vendor Advisories for CVE-2026-18283 (1)

Vendor Pages for CVE-2026-18283 (1)

Same Patch Batch · Sony · 2026-08-20 · 7 CVEs total

CVE-2026-18280 Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability
CVE-2026-18279 Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability
CVE-2026-18281 Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnera
CVE-2026-18282 Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution
CVE-2026-18278 Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerabili
CVE-2026-18284 Sony XAV-9500ES Crash Dump Handler Command Injection Local Privilege Escalation Vulnerabil

IV. Related Vulnerabilities

V. Comments for CVE-2026-18283

No comments yet


Leave a comment