Kenwood DNR1007XR Vulnerability Allows Code Execution via startUpdateProcess Flaw
A command injection vulnerability in Kenwood DNR1007XR devices, identified as ZDI-26-489, allows physically present attackers to execute arbitrary code without authentication.

A critical command injection vulnerability has been discovered in Kenwood's DNR1007XR in-car infotainment systems, allowing attackers with physical access to execute arbitrary code on the device. The vulnerability, tracked as ZDI-26-489, was disclosed by the Zero Day Initiative (ZDI) and carries a CVSS score of 6.8.
The specific flaw resides within the startUpdateProcess method of the device's firmware. Researchers found that the system fails to properly validate user-supplied input before incorporating it into a system command. This lack of sanitization enables an attacker to inject malicious commands, which are then executed with root privileges on the vulnerable device.
Exploitation of this vulnerability does not require any form of authentication, making it accessible to anyone who can physically interact with the device. This could include individuals in a vehicle's cabin or potentially through a compromised service port if accessible externally. The ability to execute arbitrary code at the root level poses a significant risk, potentially allowing for complete device compromise, data exfiltration, or the installation of persistent malware.
Kenwood has acknowledged the vulnerability and released a firmware update to address the issue. Users of the Kenwood DNR1007XR are strongly advised to apply the latest firmware update as soon as possible to mitigate the risk. Details on the update can be found on Kenwood's official customer support website.
The vulnerability was initially reported to the vendor on February 3, 2026. Following a coordinated disclosure process with ZDI, the advisory was publicly released on July 29, 2026, with an update to the advisory on the same day. The research was conducted by Sina Kheirkhah from the Summoning Team.
This discovery highlights the ongoing security challenges faced by connected automotive systems. As vehicles become more integrated with complex digital systems, vulnerabilities that allow for local code execution can have severe implications for user privacy and data security. The physical access requirement, while limiting the attack surface compared to remote exploits, still presents a tangible threat in scenarios involving vehicle theft, tampering, or unauthorized physical access.
This advisory is part of a broader trend of vulnerabilities being found in consumer electronics and automotive infotainment systems. Security researchers continue to probe these devices, often finding flaws that could be exploited to gain control or access sensitive information. The Pwn2Own competition, where similar vulnerabilities are often demonstrated, underscores the importance of robust security testing for such devices.
While the CVSS score of 6.8 indicates a 'high' severity, the lack of authentication and the potential for root-level code execution make this a critical finding for owners of the affected Kenwood model. Prompt patching remains the most effective defense against such threats.
This new advisory, ZDI-26-486, details a distinct out-of-bounds write vulnerability within the tchdr_bytestream_read function of the Kenwood DNR1007XR. While the previously reported ZDI-26-489 focused on a command injection flaw in startUpdateProcess, this vulnerability requires physical presence and no authentication to achieve arbitrary code execution in the context of root.
This advisory, ZDI-26-485, details a separate command injection vulnerability within the JKGenService component of Kenwood DNR1007XR devices. Unlike ZDI-26-489 which allows unauthenticated code execution, this flaw requires prior execution of low-privileged code on the target system to achieve privilege escalation to root. Kenwood has released a firmware update to address this specific issue.
This advisory, ZDI-26-484, details a vulnerability in the Kenwood DNR1007XR firmware update process. Attackers can create a symbolic link to abuse the service, allowing them to move files to arbitrary locations and execute code as root. The vulnerability, CVE-2026-18267, has a CVSS score of 6.8 and is exploitable by physically present attackers without authentication.