Junglewise Threat Intelligence

CVE-2026-18271: Kenwood DNR1007XR vCardParser heap buffer overflow

CVE-2026-18271 · Severity: medium · CVSS 6.8 · Published 2026-08-20

Technologies: Kenwood DNR1007XR. Vendors: Kenwood.

Executive brief

The Kenwood DNR1007XR is a navigation and multimedia receiver used in vehicles to provide GPS, audio, and infotainment functionality. This vulnerability in the vCard parsing component allows a physically present attacker to execute arbitrary code with root privileges without authentication. An attacker with access to the device can gain complete system control, potentially compromising vehicle functions, privacy, and safety.

Technical details

A heap-based buffer overflow exists in the vCardParser class of the Kenwood DNR1007XR due to insufficient validation of user-supplied strings before copying them to a heap buffer. The vulnerability requires physical access to the device and can be triggered without authentication. Exploitation allows arbitrary code execution in the context of the root user, providing complete system compromise. Kenwood released a firmware update (version 2.0.0003.1000, dated 21.07.2026) to address this and other security vulnerabilities identified during Pwn2Own Automotive 2026 testing.

Affected products

  • Kenwood DNR1007XR prior to firmware 2.0.0003.1000

Timeline

  • 2026-02-03: disclosed: Vulnerability reported to vendor
  • 2026-07-29: patched: Firmware update released (version 2.0.0003.1000)
  • 2026-07-29: advisory: Coordinated public release of ZDI advisory ZDI-26-488

References

Related threats