Description
Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.
Published: 2026-08-20
Score: 2.4 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who can physically reach the Sony XAV-9500ES can connect a specially crafted USB device. The faulty udev rule configuration then allows instantiation of USB device types that are normally restricted by the system’s authorization checks, enabling the attacker to execute actions normally protected by authentication. The weakness is an authorization control failure (CWE-285).

Affected Systems

The vulnerability affects Sony XAV-9500ES units. No specific firmware or hardware revision is listed in the data; the flaw resides in the udev rule system present on all XAV-9500ES installations.

Risk and Exploitability

The CVSS score of 2.4 reflects only moderate severity, while the EPSS score is not provided and the flaw is not catalogued in CISA KEV, suggesting a lower likelihood of widespread exploitation. The vulnerability requires physical access to connect the malicious USB device; once connected, the attacker can bypass authorization checks. The need for direct physical presence limits the threat surface, but the potential to run restricted commands under elevated privileges remains a concern for compromised device functionality.

Generated by OpenCVE AI on August 20, 2026 at 19:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest release that includes a fixed udev rule configuration (check Sony support for XAV-9500ES firmware updates).
  • If a firmware update is not available, disable or remove the vulnerable udev rules that permit creation of restricted USB device types on the system.
  • Restrict physical access to the USB ports on the XAV-9500ES, for example by using port blockers or by limiting who can attach devices to the player.

Generated by OpenCVE AI on August 20, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability. This vulnerability allows physically present attackers to bypass authorization on affected installations on Sony XAV-9500ES devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the udev rules. A crafted USB device connected to the system can trigger instantiation of otherwise restricted USB device types. An attacker can leverage this vulnerability to bypass authorization on the system. Was ZDI-CAN-28992.
Title Sony XAV-9500ES udev USB Rules Authorization Bypass Vulnerability
Weaknesses CWE-285
References
Metrics cvssV3_0

{'score': 2.4, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-20T16:19:39.821Z

Reserved: 2026-07-29T17:06:05.969Z

Link: CVE-2026-18283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:24.763

Modified: 2026-08-20T17:17:24.763

Link: CVE-2026-18283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:00:05Z

Weaknesses