CVE-2025-8651: Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability
Kenwood DMX958XR JKWifiService Command Injection Remote Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the JKWifiService. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-26307.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Was ZDI-CAN-26307: apply a compensating control for physically present attackers by restricting access to Kenwood DMX958XR devices (e.g., lock down physical access / isolate the device) to prevent exploitation of the JKWifiService command injection.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8651?
The severity of CVE-2025-8651 is considered critical due to the potential for remote code execution.
How do I fix CVE-2025-8651?
To fix CVE-2025-8651, ensure you have the latest firmware updates from Kenwood that address this vulnerability.
Who is affected by CVE-2025-8651?
CVE-2025-8651 affects users of the Kenwood DMX958XR device.
Can CVE-2025-8651 be exploited remotely?
No, CVE-2025-8651 requires physical presence to exploit the vulnerability.
What type of attack does CVE-2025-8651 involve?
CVE-2025-8651 involves command injection, allowing attackers to execute arbitrary code.