ZDI-CAN-28992: ZDI-26-476: (Pwn2Own) Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system.
Other sources
This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 2.4. The following CVEs are assigned: CVE-2026-18283.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sony XAV-9500ESto a version that resolves this vulnerability.Patch ZDI-26-476 - Compensating control
Mitigate physically present exploitation by restricting or controlling physical access to the Sony XAV-9500ES USB ports (for example, use physical port controls/disable USB device connectivity where possible).
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28992?
The severity of ZDI-CAN-28992 is rated at 2.4 according to the CVSS score.
How do I fix ZDI-CAN-28992?
Currently, there is no known patch or fix for the ZDI-CAN-28992 vulnerability, so it is recommended to limit physical access to the device.
What devices are affected by ZDI-CAN-28992?
The ZDI-CAN-28992 vulnerability affects Sony XAV-9500ES devices.
Is authentication required to exploit ZDI-CAN-28992?
No, authentication is not required to exploit the ZDI-CAN-28992 vulnerability.
What type of attack does ZDI-CAN-28992 facilitate?
The ZDI-CAN-28992 vulnerability facilitates an authorization bypass attack on affected installations.