Buffer Overflow Remote Code Execution Vulnerability in Sony XAV-9500ES
CVE-2026-18279
8.8HIGH
What is CVE-2026-18279?
The vulnerability in the Sony XAV-9500ES involves improper handling of RTSP SETUP packets, where a lack of validation of user-supplied data length can cause a buffer overflow. This flaw permits network-adjacent attackers to execute arbitrary code on the affected device without needing authentication. By leveraging this vulnerability, attackers can gain control over the device, potentially leading to further exploitation or unauthorized access.
Affected Version(s)
XAV-9500ES 3.02.00
