Kenwood DMX958XR Command Injection Vulnerability in Firmware Update Process

Vulnerability

A command injection vulnerability has been identified in the Kenwood DMX958XR model, allowing physically present attackers to execute arbitrary code with root privileges. This issue arises from inadequate validation of user-supplied strings in the firmware update process, enabling unauthorized code execution. Notably, no authentication is required to exploit this vulnerability.

Impact

Exploitation of this vulnerability could lead to unauthorized arbitrary code execution on the affected device, with the executed code running in the context of the root user.

Remediation

The vendor is currently working on a fix, but no specific patch is available yet. In the meantime, it is advised to limit interaction with the device.

Added: Aug 6, 2025, 2:44 AM
Updated: Aug 6, 2025, 2:44 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.