CVE-2026-18279
8.8Sony · XAV-9500ES
The Sony XAV-9500ES is vulnerable to a buffer overflow in its RTSP implementation, which could allow remote code execution.
Executive summary
A critical buffer overflow vulnerability in the Sony XAV-9500ES RTSP setup process could allow an adjacent attacker to execute arbitrary code.
Vulnerability
This is a classic buffer overflow (CWE-120) triggered by improper size checking during the RTSP SETUP request processing. An unauthenticated attacker on the local network can exploit this to achieve remote code execution on the device.
Business impact
The CVSS score of 8.8 indicates a high risk of total system compromise. Successful exploitation gives an attacker full control over the device, which could be used to pivot into other connected automotive systems or gain unauthorized access to user data and vehicle functions.
Remediation
Immediate Action: Check the Sony support website for firmware updates addressing the RTSP buffer overflow and apply them if available.
Proactive Monitoring: Monitor network traffic for unusual RTSP requests or unauthorized attempts to connect to the head unit from unknown devices on the local network.
Compensating Controls: Disable unnecessary network services or wireless connectivity on the device if they are not required for operation.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for remote code execution, users should treat this as a high-priority risk. If an official firmware update is released by Sony, it should be installed immediately to mitigate the risk of exploitation.