Kenwood DMX958XR Firmware Command Injection Vulnerability
CVE-2025-8641
6.8MEDIUM
What is CVE-2025-8641?
A command injection vulnerability exists in the firmware update process of Kenwood DMX958XR devices, allowing unauthorized remote execution of arbitrary code. Due to inadequate validation of user-supplied input, an attacker with physical access can exploit this flaw to execute commands with root privileges. This vulnerability poses a significant risk as it does not require authentication, emphasizing the need for immediate remediation to secure affected devices.
Affected Version(s)
DMX958XR 1.0.0005.4600 (SOC Image)