Junglewise Threat Intelligence

CVE-2026-18273: Kenwood DNR1007XR USB incorrect default permissions privilege escalation

CVE-2026-18273 · Severity: medium · CVSS 6.6 · Published 2026-08-20

Technologies: Kenwood DNR1007XR. Vendors: Kenwood.

Executive brief

The Kenwood DNR1007XR is an in-car navigation and multimedia receiver. A local privilege escalation vulnerability in USB filesystem mounting allows an attacker with low-level code execution to gain root access and run arbitrary commands. This could compromise the device's functionality, enable data theft from infotainment systems, or be combined with other exploits to gain deeper vehicle control.

Technical details

The vulnerability is a local privilege escalation caused by incorrect permissions on a USB filesystem mount point directory in the DNR1007XR. An attacker must first achieve low-privileged code execution on the target system. The flaw allows the attacker to escalate privileges to root and execute arbitrary code with root-level permissions. The attack requires physical presence or prior compromise of the device. A patch has been issued by Kenwood in firmware version 2.0.0003 and later (released July 21, 2026).

Affected products

  • Kenwood DNR1007XR

Timeline

  • 2026-02-03: disclosed: Vulnerability reported to vendor
  • 2026-07-21: patched: Firmware update released (version 2.0.0003)
  • 2026-07-29: advisory: Coordinated public disclosure via ZDI

References

Related threats