Executive brief
Kenwood DNR1007XR is a navigation and multimedia receiver used in vehicles. A vulnerability in its firmware update process allows an attacker with physical access to the device to execute code with root privileges by creating a symbolic link, potentially compromising vehicle systems and operations.
Technical details
This is a symlink-following vulnerability in the firmware update process of the Kenwood DNR1007XR receiver. The flaw allows an unauthenticated, physically present attacker to abuse the update service by creating a symbolic link, enabling arbitrary file movement to locations of attacker control. By leveraging this primitive, an attacker can execute arbitrary code in the root security context. Physical access to the device is required; no authentication is needed. Kenwood released a firmware update addressing this issue, as documented on their firmware update page.
Affected products
- Kenwood DNR1007XR Affected versions prior to 2026-08-20 firmware update
Timeline
- 2026-02-03: disclosed: Vulnerability reported to vendor
- 2026-07-29: patched: Firmware update released
- 2026-07-29: advisory: ZDI-26-484 advisory published