Sony's vulnerability footprint spans a broad portfolio of consumer electronics, audio equipment, and display technologies, with a notable concentration in networked and firmware-enabled devices such as receivers, amplifiers, and televisions. The vendor's disclosures recur across weakness classes including memory-safety issues such as buffer overflows and improper memory bounds checking, as well as path-traversal and search-path manipulation flaws that are characteristic of embedded and consumer device firmware. Vulnerabilities affecting this vendor frequently acquire public exploit code, reflecting the accessibility and appeal of consumer-grade networked devices for proof-of-concept research and weaponization. Defenders should prioritize Sony networked devices in their inventory and treat firmware updates for receivers and displays as routine patching targets; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sony over time
Signals from CVEs in this vendor scope (74 CVEs).
74 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0748HIGH Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote atta | Feb 13, 2008 | 10.0 | 47 | NO | YES |
CVE-2007-3488HIGH Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS10 and SNC-CS11 before 1.06; SNC-DF40N a | Jun 29, 2007 | 10.0 | 45 | NO | YES |
CVE-2012-0985HIGH Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wireless Wizard 1.00, 1.00_64, 1.0.1, 2.0, an | Jun 7, 2012 | 9.3 | 43 | NO | YES |
CVE-2012-2210HIGH The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCP SYN packets, as demonstrated by hping, | Apr 11, 2012 | 7.8 | 41 | NO | YES |
CVE-2007-5709HIGH Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file name in an M3U file. | Oct 30, 2007 | 9.3 | 40 | NO | YES |
CVE-2016-7834HIGH SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, SNC-EM520, SNC-EM521, SNC-ZB550, SNC-ZM55 | Apr 13, 2017 | 8.8 | 39 | NO | YES |
CVE-2013-3539MEDIUM Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, | Oct 1, 2013 | 6.8 | 35 | NO | YES |
CVE-2020-36923CRITICAL Sony BRAVIA Digital Signage 1.7.8 contains an insecure direct object reference vulnerability that allows attackers to bypass authorization controls. Attackers can access hidden sys | Jan 6, 2026 | 9.8 | 34 | NO | NO |
CVE-2006-4289HIGH Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspecified vectors. | Aug 22, 2006 | 10.0 | 32 | NO | NO |
CVE-2024-23922MEDIUM Sony XAV-AX5500 Insufficient Firmware Update Validation Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on aff | Sep 23, 2024 | 6.8 | 31 | NO | YES |
Signals from CVEs in this vendor scope (74 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sony.
Media articles that mention a CVE ID that affects a product developed by Sony — matched by CVE ID, not by vendor name.