ZDI-26-484: (Pwn2Own) Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability
This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DNR1007XR devices. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.8. The following CVEs are assigned: CVE-2026-18267.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-484?
The severity of ZDI-26-484 is rated at 6.8 on the CVSS scale.
How do I fix ZDI-26-484?
To fix ZDI-26-484, you should apply the latest firmware update provided by Kenwood for the DNR1007XR device.
Who can exploit ZDI-26-484?
ZDI-26-484 can be exploited by physically present attackers without the need for authentication.
What devices are affected by ZDI-26-484?
ZDI-26-484 affects Kenwood DNR1007XR devices that have not been updated to the latest firmware.
What type of vulnerability is ZDI-26-484?
ZDI-26-484 is a code execution vulnerability that allows arbitrary code execution on the affected device.