CVE-2018-16594: Path Traversal

Published Jun 19, 2019
·
Updated

The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.

Affected Software

105 affected components
Sony R5c Firmware<8.590
Sony Kdl-32r500c
Sony Kdl-32r503c
Sony Kdl-32r505c
Sony Kdl-40r550c
Sony Kdl-40r553c
Sony Kdl-40r555c
Sony Kdl-48r550c
Sony Kdl-48r553c
Sony Kdl-48r555c
Sony Wd75 Firmware<8.216
Sony Kdl-32wd750
Sony Kdl-32wd751
Sony Kdl-32wd752
Sony Kdl-32wd753
Sony Kdl-32wd754
Sony Kdl-32wd755
Sony Kdl-32wd756
Sony Kdl-32wd757
Sony Kdl-32wd758
Sony Kdl-32wd759
Sony Kdl-43wd750
Sony Kdl-43wd751
Sony Kdl-43wd752
Sony Kdl-43wd753
Sony Kdl-43wd754
Sony Kdl-43wd755
Sony Kdl-43wd756
Sony Kdl-43wd757
Sony Kdl-43wd758
Sony Kdl-43wd759
Sony Kdl-49wd750
Sony Kdl-49wd751
Sony Kdl-49wd752
Sony Kdl-49wd753
Sony Kdl-49wd754
Sony Kdl-49wd755
Sony Kdl-49wd756
Sony Kdl-49wd757
Sony Kdl-49wd758
Sony Kdl-49wd759
Sony Wd65 Firmware<8.216
Sony Kdl-40wd650
Sony Kdl-40wd653
Sony Kdl-40wd655
Sony Kdl-48wd650
Sony Kdl-48wd653
Sony Kdl-48wd655
Sony Xe70 Firmware<8.764
Sony Kd-43xe7000
Sony Kd-43xe7002
Sony Kd-43xe7003
Sony Kd-43xe7004
Sony Kd-43xe7005
Sony Kd-43xe7073
Sony Kd-43xe7077
Sony Kd-43xe7093
Sony Kd-43xe7096
Sony Kd-49xe7000
Sony Kd-49xe7002
Sony Kd-49xe7003
Sony Kd-49xe7004
Sony Kd-49xe7005
Sony Kd-49xe7073
Sony Kd-49xe7077
Sony Kd-49xe7093
Sony Kd-49xe7096
Sony Kd-55xe7000
Sony Kd-55xe7002
Sony Kd-55xe7003
Sony Kd-55xe7004
Sony Kd-55xe7005
Sony Kd-55xe7073
Sony Kd-55xe7077
Sony Kd-55xe7093
Sony Kd-55xe7096
Sony Kd-65xe7002
Sony Kd-65xe7003
Sony Kd-65xe7004
Sony Kd-65xe7005
Sony Kd-65xe7093
Sony Kd-65xe7096
Sony Xf70 Firmware<8.764
Sony Xf70
Sony We75 Firmware<8.464
Sony Kdl-43we750
Sony Kdl-43we753
Sony Kdl-43we754
Sony Kdl-43we755
Sony Kdl-49we750
Sony Kdl-49we753
Sony Kdl-49we754
Sony Kdl-49we755
Sony We6 Firmware<8.464
Sony Kdl-32we610
Sony Kdl-32we613
Sony Kdl-32we615
Sony Kdl-40we660
Sony Kdl-40we663
Sony Kdl-40we665
Sony Kdl-49we660
Sony Kdl-49we663
Sony Kdl-49we665
Sony Wf6 Firmware<8.464
Sony Wf6

Event History

Jun 19, 2019
CVE Published
via MITRE·06:13 PM
Data Sourced
via MITRE·06:13 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2018-16594?

CVE-2018-16594 is classified as a high-severity vulnerability due to its potential for unauthorized file access.

2

How do I fix CVE-2018-16594?

To mitigate CVE-2018-16594, update the affected Sony Bravia TV firmware to version 8.590 or later.

3

What devices are affected by CVE-2018-16594?

CVE-2018-16594 impacts Sony Bravia TV devices running firmware versions up to 8.587.

4

Can CVE-2018-16594 be exploited remotely?

Yes, CVE-2018-16594 can be exploited remotely, allowing attackers to access restricted files.

5

Is there a workaround for CVE-2018-16594?

There are no specific workarounds for CVE-2018-16594 other than applying the firmware update as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203