Buffer Overflow Vulnerability in Sony XAV-9500ES Devices
CVE-2026-18280
3.9LOW
What is CVE-2026-18280?
A vulnerability in Sony XAV-9500ES devices arises from the improper handling of NMEA data by the gpsd daemon, allowing attackers with physical access to execute arbitrary code. The flaw is due to inadequate validation of user-supplied data length before it is copied to a fixed-length buffer. This oversight can be exploited in conjunction with additional vulnerabilities, enabling unauthorized code execution within the context of the gpsd daemon.
Affected Version(s)
XAV-9500ES 3.02.00
