Command Injection Vulnerability in Kenwood DMX958XR Firmware
CVE-2025-8635
6.8MEDIUM
What is CVE-2025-8635?
A command injection vulnerability exists within the firmware update process of Kenwood DMX958XR devices. Attackers with physical access can exploit this flaw to execute arbitrary code without requiring authentication. The lack of proper validation of user-supplied input during the firmware update permits unauthorized execution of commands, potentially compromising the device and resulting in unauthorized access. This vulnerability highlights the importance of securing firmware processes and validating inputs to prevent exploitation.
Affected Version(s)
DMX958XR 1.0.0005.4600 (SOC Image)