Command Injection Vulnerability in Kenwood DMX958XR Firmware
CVE-2025-8642
6.8MEDIUM
What is CVE-2025-8642?
The Kenwood DMX958XR firmware is susceptible to a command injection vulnerability during the firmware update process. This flaw arises from insufficient validation of user-supplied strings used in system calls, potentially allowing local attackers to execute arbitrary code with root privileges on the device. As there is no authentication required, exploiting this vulnerability poses significant risks to device integrity.
Affected Version(s)
DMX958XR 1.0.0005.4600 (SOC Image)