Description
Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of Bluetooth L2CAP packets. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Was ZDI-CAN-28990.
Published: 2026-08-20
Score: 3.5 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability originates from an out-of-bounds read in the prh_l2_decode_packet function of Sony XAV-9500ES devices. The flaw stems from the lack of validation of Bluetooth L2CAP packet data and can allow an attacker to read memory beyond the intended buffer. The disclosed data could reveal sensitive information on the device. While the vulnerability alone does not provide direct execution capability, the description indicates that it could be leveraged alongside other weaknesses to achieve arbitrary code execution in the device’s context.

Affected Systems

Sony XAV-9500ES media players are the affected hardware. No specific firmware or software version is listed, so all current devices bearing this product designation are assumed to be vulnerable until a patch is released.

Risk and Exploitability

The CVSS score of 3.5 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker to physically bring a malicious Bluetooth device into pairing proximity with the target, meaning the attack vector is local and network‑adjacent. The need for pairing reduces the likelihood of widespread exploitation but does not eliminate the risk, especially if operators neglect to restrict Bluetooth usage.

Generated by OpenCVE AI on August 20, 2026 at 19:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable or tightly restrict Bluetooth pairing on the device, allowing only trusted devices to connect.
  • Apply any available firmware or software update that corrects the out‑of‑bounds read flaw.
  • Monitor the device for abnormal pairing attempts or unauthorized Bluetooth activity to detect potential exploitation attempts.

Generated by OpenCVE AI on August 20, 2026 at 19:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sony XAV-9500ES devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in order to exploit this vulnerability. The specific flaw exists within the handling of Bluetooth L2CAP packets. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the device. Was ZDI-CAN-28990.
Title Sony XAV-9500ES prh_l2_decode_packet Out-Of-Bounds Read Information Disclosure Vulnerability
Weaknesses CWE-125
References
Metrics cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-20T16:18:52.440Z

Reserved: 2026-07-29T17:05:47.697Z

Link: CVE-2026-18278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:24.123

Modified: 2026-08-20T17:17:24.123

Link: CVE-2026-18278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:00:05Z

Weaknesses