Local Privilege Escalation Vulnerability in Kenwood DNR1007XR Devices
CVE-2026-18268

7HIGH

Key Information:

Vendor

Kenwood

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18268?

The Kenwood DNR1007XR devices have a vulnerability within the JKGenService, which permits local attackers to escalate privileges. This flaw arises due to inadequate validation of a user-supplied string before it is utilized to execute system calls. Successful exploitation requires an attacker to run low-privileged code on the system, allowing them to potentially execute arbitrary code with elevated privileges. This could pose significant risks to the device's security and operational integrity.

Affected Version(s)

DNR1007XR 1.7.0003.1000

References

CVSS V3.0

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.