Executive brief
The Kenwood DNR1007XR is a navigation and multimedia receiver for vehicles. A flaw in the udhcpd service (which manages DHCP network configuration) has incorrect file or directory permissions that allow a local attacker with low-privilege access to escalate to root, potentially enabling complete control over the device and access to sensitive navigation data or vehicle systems.
Technical details
The vulnerability is an incorrect permission assignment flaw in the udhcpd service running on Kenwood DNR1007XR devices. The service fails to properly restrict access to a resource (likely a file or directory), allowing a local attacker with low-privilege code execution to escalate privileges to root. The attack vector is local-only and requires the attacker to already have the ability to execute code on the system with a low privilege level. Exploitation results in full code execution in the root context, compromising device integrity and confidentiality. Kenwood released a firmware update (version 2.0.0003 published 2026-07-21) to address this vulnerability.
Affected products
- Kenwood DNR1007XR prior to firmware version 2.0.0003
Timeline
- 2026-02-03: disclosed: Vulnerability reported to Kenwood by Slow Horses of Qrious Secure
- 2026-07-21: patched: Firmware update released addressing the vulnerability
- 2026-07-29: advisory: ZDI-26-487 / ZDI-CAN-29111 coordinated public disclosure