Junglewise Threat Intelligence

CVE-2026-18272: Kenwood DNR1007XR command injection in startUpdateProcess

CVE-2026-18272 · Severity: medium · CVSS 6.8 · Published 2026-08-20

Technologies: Kenwood DNR1007XR. Vendors: Kenwood.

Executive brief

The Kenwood DNR1007XR is a navigation and multimedia receiver used in vehicles. This vulnerability allows an attacker with physical access to the device to execute arbitrary code with root privileges by injecting commands into the firmware update process. Since no authentication is required, any person with physical access to the vehicle can exploit this to gain complete control of the infotainment system.

Technical details

This is a command injection vulnerability in the startUpdateProcess method of the Kenwood DNR1007XR firmware. The root cause is insufficient validation of user-supplied input before passing it to a system call, allowing an attacker to inject arbitrary shell commands. The attack vector requires physical access to the device (AV:P), but no authentication or user interaction is necessary. An attacker can leverage this flaw to execute arbitrary commands in the context of root, achieving complete code execution. A firmware update was released in July 2026 to address this vulnerability.

Affected products

  • Kenwood DNR1007XR <2020 firmware update (2026-07-29)

Timeline

  • 2026-02-03: disclosed: Vulnerability reported to Kenwood
  • 2026-07-29: patched: Firmware update released
  • 2026-07-29: advisory: ZDI-26-489 advisory published

References

Related threats