Heap-based Buffer Overflow in Kenwood DNR1007XR Devices
CVE-2026-18271

6.8MEDIUM

Key Information:

Vendor

Kenwood

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-18271?

A vulnerability exists in Kenwood DNR1007XR devices due to improper validation of user-supplied input within the vCardParser class. This flaw allows physically present attackers to exploit the device by executing arbitrary code, enabling potential unauthorized access and control. Authentication is not required, making this vulnerability particularly concerning. Users are urged to review the firmware updates provided by Kenwood to mitigate this risk.

Affected Version(s)

DNR1007XR 1.7.0003.1000

References

CVSS V3.0

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.