ZDI-CAN-29072: ZDI-26-474: (Pwn2Own) Sony XAV-9500ES l2_reassemble_sdu Heap-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.0. The following CVEs are assigned: CVE-2026-18281.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29072?
The severity of ZDI-CAN-29072 is rated at 68, indicating a significant risk level.
How do I fix ZDI-CAN-29072?
To mitigate ZDI-CAN-29072, ensure your Sony XAV-9500ES device is updated with the latest firmware provided by Sony.
What type of vulnerability is ZDI-CAN-29072?
ZDI-CAN-29072 is a heap-based buffer overflow vulnerability that allows remote code execution.
Who can exploit ZDI-CAN-29072?
Network-adjacent attackers with the ability to pair a malicious Bluetooth device to the Sony XAV-9500ES can exploit ZDI-CAN-29072.
What devices are affected by ZDI-CAN-29072?
ZDI-CAN-29072 specifically affects the Sony XAV-9500ES device.