๐Ÿ” CVE Alert

CVE-2026-18283

LOW 2.4

Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability

CVSS Score
2.4
EPSS Score
0.0%
EPSS Percentile
0th

Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.

CWE CWE-285
Vendor sony
Product xav-9500es
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for sony xav-9500es

Be the first to know when new low vulnerabilities affecting sony xav-9500es are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected Versions

Sony / XAV-9500ES
3.02.00

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
zerodayinitiative.com: https://www.zerodayinitiative.com/advisories/ZDI-26-476/ sony.com: https://www.sony.com/electronics/support/mobile-cd-players-digital-media-players-xav-series/xav-9500es/software/00274922