Impact
Kenwood DNR1007XR devices contain a command injection flaw in the startUpdateProcess method, where a user‑supplied string is executed without proper validation. This allows an attacker to run arbitrary system commands with root privileges, effectively giving full control over the device.
Affected Systems
Kenwood DNR1007XR devices are affected. No additional vendor or version specifics are provided in the available data.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.8, indicating a moderate risk. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. Exploitation does not require authentication and can be achieved by a physically present attacker, but it cannot be triggered remotely. Because the attack vector is local, the risk is confined to environments where physical access to the device is possible; once accessed, an attacker can fully control the device, increasing the potential impact in critical installations.
OpenCVE Enrichment