CVE-2025-8649: (0Day) (Pwn2Own) Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the JKWifiService. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26305.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-CAN-26305 - Compensating control
Mitigate publicly reachable exploitation by restricting physical/remote access to affected Kenwood DMX958XR devices (attack requires physically present access per the description).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8649?
The severity of CVE-2025-8649 is critical due to its potential for remote code execution.
What devices are affected by CVE-2025-8649?
CVE-2025-8649 affects the Kenwood DMX958XR devices.
How do I fix CVE-2025-8649?
To fix CVE-2025-8649, update the Kenwood DMX958XR firmware to the latest version provided by the vendor.
Can CVE-2025-8649 be exploited without authentication?
Yes, CVE-2025-8649 can be exploited without authentication, allowing unauthorized access.
What type of vulnerability is CVE-2025-8649?
CVE-2025-8649 is a command injection vulnerability that leads to remote code execution.