Executive brief
The Kenwood DNR1007XR is a navigation and multimedia receiver used in vehicles to provide GPS, audio, and infotainment functionality. This vulnerability in the vCard parsing component allows a physically present attacker to execute arbitrary code with root privileges without authentication. An attacker with access to the device can gain complete system control, potentially compromising vehicle functions, privacy, and safety.
Technical details
A heap-based buffer overflow exists in the vCardParser class of the Kenwood DNR1007XR due to insufficient validation of user-supplied strings before copying them to a heap buffer. The vulnerability requires physical access to the device and can be triggered without authentication. Exploitation allows arbitrary code execution in the context of the root user, providing complete system compromise. Kenwood released a firmware update (version 2.0.0003.1000, dated 21.07.2026) to address this and other security vulnerabilities identified during Pwn2Own Automotive 2026 testing.
Affected products
- Kenwood DNR1007XR prior to firmware 2.0.0003.1000
Timeline
- 2026-02-03: disclosed: Vulnerability reported to vendor
- 2026-07-29: patched: Firmware update released (version 2.0.0003.1000)
- 2026-07-29: advisory: Coordinated public release of ZDI advisory ZDI-26-488