ZDI-26-485: (Pwn2Own) Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0. The following CVEs are assigned: CVE-2026-18268.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-485?
The severity of ZDI-26-485 is rated with a CVSS score of 7.0, indicating high risk.
How do I fix ZDI-26-485?
To mitigate ZDI-26-485, ensure that the Kenwood DNR1007XR firmware is updated to the latest version provided by the manufacturer.
Who is affected by ZDI-26-485?
ZDI-26-485 affects installations of the Kenwood DNR1007XR devices that allow local privilege escalation.
What type of attack does ZDI-26-485 involve?
ZDI-26-485 involves command injection that enables local attackers to escalate their privileges.
What are the prerequisites for exploiting ZDI-26-485?
An attacker must first be able to execute low-privileged code on the target system to exploit ZDI-26-485.