ZDI-26-473: (Pwn2Own) Sony XAV-9500ES gpsd Buffer Overflow Arbitrary Code Execution Vulnerability
This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 3.9. The following CVEs are assigned: CVE-2026-18280.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-473?
The severity of ZDI-26-473 is rated at a CVSS score of 3.9.
How do I fix ZDI-26-473?
To fix ZDI-26-473, you should apply any available firmware updates from Sony for the XAV-9500ES device.
Who can exploit ZDI-26-473?
ZDI-26-473 can be exploited by physically present attackers without the need for authentication.
What type of vulnerability is ZDI-26-473?
ZDI-26-473 is a buffer overflow vulnerability that allows arbitrary code execution.
What impact does ZDI-26-473 have on Sony XAV-9500ES devices?
The impact of ZDI-26-473 is that an attacker can execute arbitrary code, potentially compromising the device's functionality.