索尼 XAV-9500ES 崩溃转储处理程序命令注入本地权限提升漏洞。该漏洞允许本地攻击者在受影响的索尼 XAV-9500ES 设备安装环境中提升权限。攻击者必须首先能够以低权限在目标系统上执行代码,才能利用此漏洞。 该特定漏洞存在于进程崩溃转储的处理过程中。问题源于在对用户提供的字符串进行使用以执行系统调用之前,缺乏适当的验证。攻击者可以利用此漏洞以 root 用户上下文提升权限并执行任意代码。该漏洞编号为 ZDI-CAN-29061。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Sony | XAV-9500ES | 3.02.00 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Sony | XAV-9500ES | 3.02.00 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-18283 | Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability | |
| CVE-2026-18280 | Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability | |
| CVE-2026-18279 | Sony XAV-9500ES RTSP SETUP Buffer Overflow Remote Code Execution Vulnerability | |
| CVE-2026-18281 | Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnera | |
| CVE-2026-18282 | Sony XAV-9500ES AVRCP_Br_Response_Parser Heap-based Buffer Overflow Remote Code Execution | |
| CVE-2026-18278 | Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerabili |
No comments yet