Executive brief
The Kenwood DNR1007XR is a navigation and multimedia receiver system used in vehicles. A buffer overflow vulnerability in the firmware's file parsing allows an attacker with physical access to the device to execute arbitrary code with root privileges, potentially gaining complete control of the in-vehicle infotainment system and any connected vehicle functions.
Technical details
This is a classic out-of-bounds write (buffer overflow) vulnerability in the tchdr_bytestream_read function within the DNR1007XR firmware. The root cause is insufficient validation of user-supplied data, allowing an attacker to write beyond the bounds of an allocated buffer. The attack vector is physical—an attacker must have hands-on access to the device, typically via USB or similar media interfaces used for firmware updates or media playback. No authentication is required to trigger the vulnerability. Successful exploitation results in arbitrary code execution in the root security context, granting the attacker full control of the device. Kenwood released a firmware update (version 2_0_0003 as of 2026-07-29) to address this and related vulnerabilities.
Affected products
- Kenwood DNR1007XR prior to 2026-07-29 firmware update
Timeline
- 2026-02-03: disclosed: Vulnerability reported to Kenwood
- 2026-07-29: patched: Firmware update released (S_V2_0_0003_1000.zip)
- 2026-07-29: advisory: ZDI-26-486 / ZDI-CAN-28980 public disclosure