Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sony

First CVE: Dec 31, 2002Active for: 24 yearsTotal CVEs: 74
49.4
VTI Score
High

Sony's vulnerability footprint spans a broad portfolio of consumer electronics, audio equipment, and display technologies, with a notable concentration in networked and firmware-enabled devices such as receivers, amplifiers, and televisions. The vendor's disclosures recur across weakness classes including memory-safety issues such as buffer overflows and improper memory bounds checking, as well as path-traversal and search-path manipulation flaws that are characteristic of embedded and consumer device firmware. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility and appeal of consumer-grade networked devices for proof-of-concept research and weaponization. Defenders should prioritize Sony networked devices in their inventory and treat firmware updates for receivers and displays as routine patching targets; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
74
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sony over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Jan 6, 2026
199 days ago

Products(413 total)

Top CVEs

Signals from CVEs in this vendor scope (74 CVEs).

74 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2008-0748HIGH
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote atta
Feb 13, 200810.047NOYES
CVE-2007-3488HIGH
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N a
Jun 29, 200710.045NOYES
CVE-2012-0985HIGH
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, an
Jun 7, 20129.343NOYES
CVE-2012-2210HIGH
The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCP SYN packets, as demonstrated by hping,
Apr 11, 20127.841NOYES
CVE-2007-5709HIGH
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file.
Oct 30, 20079.340NOYES
CVE-2016-7834HIGH
SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM55
Apr 13, 20178.839NOYES
CVE-2013-3539MEDIUM
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T,
Oct 1, 20136.835NOYES
CVE-2020-36923CRITICAL
Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden sys
Jan 6, 20269.834NONO
CVE-2006-4289HIGH
Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspecified vectors.
Aug 22, 200610.032NONO
CVE-2024-23922MEDIUM
Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on aff
Sep 23, 20246.831NOYES
View all 74 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products74 CVEs
34%
57%
8%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local17 (23.0%)
Network20 (27.0%)
Unknown20 (27.0%)
Physical4 (5.4%)
Adjacent Network13 (17.6%)
Attack Complexity
Low45 (60.8%)
High9 (12.2%)
Unknown20 (27.0%)
User Interaction
None38 (51.4%)
Unknown20 (27.0%)
Required16 (21.6%)
Privileges Required
Low4 (5.4%)
High4 (5.4%)
None46 (62.2%)
Unknown20 (27.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (74 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.4% of CVEs· 95th percentile
ExploitDB
7 CVEs
9.5% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sony.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sony — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sony's Products

View all 8 CNAs →

Top CWEs