Firmware Update Command Injection in Kenwood DMX958XR by Kenwood
CVE-2025-8638

6.8MEDIUM

Key Information:

Vendor

Kenwood

Status
Vendor
CVE Published:
6 August 2025

What is CVE-2025-8638?

The Kenwood DMX958XR firmware contains a command injection vulnerability that permits unauthorized physical access to execute arbitrary code on affected devices. This flaw arises during the firmware update process, where the system inadequately validates user-supplied input prior to executing system commands. Exploiting this vulnerability can allow an attacker to gain root access, posing significant security risks.

Affected Version(s)

DMX958XR 1.0.0005.4600 (SOC Image)

References

CVSS V3.0

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8638 : Firmware Update Command Injection in Kenwood DMX958XR by Kenwood