Description
Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the configuration of the mount point for the USB filesystem. The issue results from incorrect permissions on a directory used by the product. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-29070.
Published: 2026-08-20
Score: 6.6 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises from incorrect permissions on a directory used for mounting USB filesystems in Kenwood DNR1007XR devices. When those permissions are overly permissive, a local attacker who has already achieved low‑privileged code execution can manipulate the filesystem to elevate privileges to root, allowing arbitrary code execution and compromising the device’s confidentiality, integrity, and availability.

Affected Systems

Kenwood DNR1007XR devices are affected. The data set does not list specific firmware or hardware revisions, so any implementation of this model that exposes a USB mount point with the described permission configuration is potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.6 indicates a medium severity risk. The EPSS score is not available, which limits the ability to gauge current exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a physically present threat actor who can already run code at a low privilege level on the device, implying a local physical attack vector. While this raises the barrier to exploitation, the flaw remains exploitable when local access is feasible, resulting in a moderate risk level for environments that do not enforce strict physical security or timely firmware updates.

Generated by OpenCVE AI on August 20, 2026 at 20:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Observe Kenwood’s product support page to locate the latest firmware that corrects the USB mount permission configuration and install the update on all affected devices.
  • If a firmware update is not immediately available, modify the USB filesystem mount point permissions to a restrictive setting that aligns with the product’s security guidelines to prevent unintended write access.
  • Implement physical security controls that restrict unauthorized personnel from accessing the device to mitigate the risk of an attacker gaining the local code execution prerequisite.

Generated by OpenCVE AI on August 20, 2026 at 20:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows physically present attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the mount point for the USB filesystem. The issue results from incorrect permissions on a directory used by the product. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root. Was ZDI-CAN-29070.
Title Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 6.6, 'vector': 'CVSS:3.0/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-08-20T16:14:49.100Z

Reserved: 2026-07-29T17:03:02.033Z

Link: CVE-2026-18273

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T17:17:23.880

Modified: 2026-08-20T17:17:23.880

Link: CVE-2026-18273

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T20:45:04Z

Weaknesses
  • CWE-276

    Incorrect Default Permissions