CVE-2026-18270: (Pwn2Own) Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability
Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the udhcpd service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of root. Was ZDI-CAN-29111.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-CAN-29111 - Compensating control
Mitigate the local privilege escalation by restricting who can run low-privileged code on the Kenwood DNR1007XR device (e.g., limit local access to trusted users/processes so the prerequisite access for exploiting the udhcpd issue is not available).
Event History
Frequently Asked Questions
Who is exposed to this vulnerability?
Affected Kenwood DNR1007XR devices are exposed only to attackers who can already execute code locally with low privileges. It is not described as remotely exploitable without first obtaining that local code-execution capability.
What level of access can an attacker gain?
An attacker can exploit the incorrect permissions on a resource used by udhcpd to escalate from low-privileged code execution to code execution in the context of root.
Which component should be investigated when assessing exposure?
The affected component is the udhcpd service. Assessment should focus on whether the device is an affected Kenwood DNR1007XR installation and whether an attacker could obtain low-privileged local code execution.