Executive brief
The Kenwood DNR1007XR is a car navigation and multimedia receiver used in vehicles. A command injection flaw in the JKGenService component allows a local attacker who can already run code on the device to escalate privileges and execute arbitrary commands with root access, compromising vehicle safety systems and infotainment functionality.
Technical details
This vulnerability is a command injection flaw in the JKGenService component of the Kenwood DNR1007XR in-vehicle multimedia receiver. The vulnerability stems from insufficient validation of user-supplied input before passing it to a system call, allowing an attacker to inject arbitrary commands. Exploitation requires prior local code execution with at least low-privilege access on the target device. A successful exploit enables an attacker to escalate privileges and execute arbitrary code with root-level permissions. The CVE CVSS score of 7.0 reflects the high impact (confidentiality, integrity, availability) combined with the requirement for local access and low-privilege starting context. Kenwood released a firmware patch as of 2026-07-29 to address this issue.
Affected products
- Kenwood DNR1007XR prior to firmware version 2020F (2026-07-29 patch)
Timeline
- 2026-02-03: disclosed: Vulnerability reported to vendor
- 2026-07-29: advisory: Coordinated public disclosure via ZDI-26-485
- 2026-07-29: patched: Firmware update released (Version 2020F or later)