CVE-2025-8650: (0Day) (Pwn2Own) Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution Vulnerability
Kenwood DMX958XR libSystemLib Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the firmware update process. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26306.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-CAN-26306 - Compensating control
Mitigate physically present exploitation by restricting physical access to affected Kenwood DMX958XR devices (e.g., lock down device locations and limit access to authorized personnel only).
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8650?
CVE-2025-8650 is considered a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-8650?
To fix CVE-2025-8650, update the Kenwood DMX958XR device firmware to the latest version provided by the manufacturer.
Who is affected by CVE-2025-8650?
Devices that run the Kenwood DMX958XR software are affected by CVE-2025-8650.
Can CVE-2025-8650 be exploited remotely?
Yes, CVE-2025-8650 can be exploited remotely by attackers without authentication.
What are the potential impacts of CVE-2025-8650?
The potential impacts of CVE-2025-8650 include unauthorized access and execution of arbitrary code on vulnerable devices.