Junglewise Threat Intelligence

CVE-2026-18279: Sony XAV-9500ES RTSP buffer overflow remote code execution

CVE-2026-18279 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: Sony XAV-9500ES. Vendors: Sony.

Executive brief

The Sony XAV-9500ES is a mobile media player and receiver unit commonly installed in vehicles. A buffer overflow vulnerability in its RTSP (streaming protocol) handler allows attackers on the local network to execute arbitrary code on the device without authentication, potentially compromising vehicle infotainment systems and the data they contain.

Technical details

A buffer overflow vulnerability exists in the RTSP SETUP packet handler of the Sony XAV-9500ES. The flaw results from insufficient validation of user-supplied data length before copying it into a fixed-length stack or heap buffer. An attacker on the adjacent network can send a malformed RTSP SETUP packet with an oversized payload to trigger the overflow and achieve arbitrary code execution in the context of the device. No authentication is required. The vendor has issued a software update to address this issue.

Affected products

  • Sony XAV-9500ES

Timeline

  • 2026-03-19: disclosed: Vulnerability reported to vendor
  • 2026-07-29: advisory: Coordinated public release
  • 2026-07-29: patched: Sony issued an update

References

Related threats