Kenwood DMX958XR Command Injection Vulnerability in Firmware Update Process

Vulnerability

A command injection vulnerability has been identified in the Kenwood DMX958XR model, allowing physically present attackers to execute arbitrary code on the device. This issue arises from inadequate validation of user-supplied strings during the firmware update process, enabling code execution with root privileges.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of arbitrary code on the affected device, with root-level privileges.

Remediation

Due to the nature of this vulnerability, the primary recommendation is to limit physical access to the device.

Added: Aug 6, 2025, 3:04 AM
Updated: Aug 6, 2025, 3:04 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.