Browse all 12 CVE security advisories affecting Sony. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Sony operates primarily in consumer electronics, entertainment, and gaming, with products ranging from PlayStation consoles to media services. Historically, the company's systems have been vulnerable to remote code execution, cross-site scripting, and privilege escalation, often through web interfaces and firmware flaws. Notable incidents include the 2011 PlayStation Network breach exposing 77 million users' data, and multiple vulnerabilities in its cameras and IoT devices. Despite improvements, Sony's current 12 CVEs indicate ongoing security challenges, particularly in firmware and web application components. The company's diverse product ecosystem creates complex attack surfaces, requiring continuous vulnerability management to protect user data and maintain system integrity.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-5475 | Sony XAV-AX8500 Bluetooth Packet Handling Integer Overflow Remote Code Execution Vulnerability — XAV-AX8500CWE-190 | 8.8AI | HighAI | 2025-06-21 |
| CVE-2025-5477 | Sony XAV-AX8500 Bluetooth L2CAP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability — XAV-AX8500CWE-122 | 8.8AI | HighAI | 2025-06-21 |
| CVE-2025-5478 | Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability — XAV-AX8500CWE-190 | 8.8AI | HighAI | 2025-06-21 |
| CVE-2025-5479 | Sony XAV-AX8500 Bluetooth AVCTP Protocol Heap-based Buffer Overflow Remote Code Execution Vulnerability — XAV-AX8500CWE-122 | 8.8AI | HighAI | 2025-06-21 |
| CVE-2025-5476 | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability — XAV-AX8500CWE-653 | 8.8AI | HighAI | 2025-06-21 |
| CVE-2025-5820 | Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability — XAV-AX8500CWE-288 | 8.8AI | HighAI | 2025-06-21 |
This page lists every published CVE security advisory associated with Sony. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.