Command Injection Vulnerability in Kenwood DMX958XR Firmware
CVE-2025-8642

6.8MEDIUM

Key Information:

Vendor

Kenwood

Status
Vendor
CVE Published:
6 August 2025

What is CVE-2025-8642?

The Kenwood DMX958XR firmware is susceptible to a command injection vulnerability during the firmware update process. This flaw arises from insufficient validation of user-supplied strings used in system calls, potentially allowing local attackers to execute arbitrary code with root privileges on the device. As there is no authentication required, exploiting this vulnerability poses significant risks to device integrity.

Affected Version(s)

DMX958XR 1.0.0005.4600 (SOC Image)

References

CVSS V3.0

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-8642 : Command Injection Vulnerability in Kenwood DMX958XR Firmware