Junglewise Threat Intelligence

CVE-2026-18268: Kenwood DNR1007XR JKGenService command injection local privilege escalation

CVE-2026-18268 · Severity: high · CVSS 7 · Published 2026-08-20

Technologies: Kenwood DNR1007XR. Vendors: Kenwood.

Executive brief

The Kenwood DNR1007XR is a car navigation and multimedia receiver used in vehicles. A command injection flaw in the JKGenService component allows a local attacker who can already run code on the device to escalate privileges and execute arbitrary commands with root access, compromising vehicle safety systems and infotainment functionality.

Technical details

This vulnerability is a command injection flaw in the JKGenService component of the Kenwood DNR1007XR in-vehicle multimedia receiver. The vulnerability stems from insufficient validation of user-supplied input before passing it to a system call, allowing an attacker to inject arbitrary commands. Exploitation requires prior local code execution with at least low-privilege access on the target device. A successful exploit enables an attacker to escalate privileges and execute arbitrary code with root-level permissions. The CVE CVSS score of 7.0 reflects the high impact (confidentiality, integrity, availability) combined with the requirement for local access and low-privilege starting context. Kenwood released a firmware patch as of 2026-07-29 to address this issue.

Affected products

  • Kenwood DNR1007XR prior to firmware version 2020F (2026-07-29 patch)

Timeline

  • 2026-02-03: disclosed: Vulnerability reported to vendor
  • 2026-07-29: advisory: Coordinated public disclosure via ZDI-26-485
  • 2026-07-29: patched: Firmware update released (Version 2020F or later)

References

Related threats