PT-2025-32058 · Kenwood · Kenwood Dmx958Xr

Elias Ikkela-Koski

·

Published

2025-08-05

·

Updated

2025-08-20

·

CVE-2025-8649

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Kenwood DMX958XR (affected versions not specified)
Description This issue allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices without authentication. The flaw resides within the JKWifiService due to insufficient validation of user-supplied strings before executing system calls, enabling an attacker to execute code in the context of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-8649
ZDI-25-797

Affected Products

Kenwood Dmx958Xr