Kenwood DNR1007XR Vulnerability Allows Local Privilege Escalation via USB Permissions
A local privilege escalation vulnerability in Kenwood DNR1007XR devices, identified as ZDI-26-490, allows physically present attackers to gain root-level access by exploiting incorrect USB permissions.

A critical vulnerability affecting Kenwood DNR1007XR devices has been disclosed by the Zero Day Initiative (ZDI), allowing attackers with physical access and low-privilege code execution capabilities to escalate their privileges to root.
The vulnerability, tracked as ZDI-26-490 and assigned CVE-2026-18273, stems from incorrect default permissions on the USB filesystem mount point. This misconfiguration enables an attacker who has already gained initial low-privilege access to the device to exploit the flaw and execute arbitrary code with elevated permissions.
The Zero Day Initiative has assigned this vulnerability a CVSS score of 6.6, indicating a moderate-to-high severity risk. The requirement for physical presence and prior low-privilege code execution limits the attack vector, but the potential for full system compromise remains significant.
Kenwood has acknowledged the vulnerability and released a firmware update to address the issue. Users of the Kenwood DNR1007XR are strongly advised to apply the available update to mitigate the risk of exploitation. Further details on the update can be found on Kenwood's official customer support website.
The vulnerability was initially reported to Kenwood on February 3, 2026. Following coordinated disclosure efforts, the advisory was publicly released on July 29, 2026, with an update to the advisory also published on the same day.
This discovery highlights the ongoing security challenges in embedded automotive and consumer electronics devices, where physical access vulnerabilities can still lead to significant system compromise if not properly secured. The exploit chain requires a combination of physical access and the ability to run initial code, making it less likely for remote attackers but a considerable threat in scenarios involving device tampering or theft.
The research was conducted by TienPP from the FPT NightWolf Team, who has been credited for discovering and reporting this security flaw. The disclosure process followed standard industry practices to ensure vendors have adequate time to develop and deploy patches before public release.
This incident serves as a reminder for manufacturers to rigorously audit default permissions and access controls, especially for interfaces like USB that can be physically accessed and potentially manipulated by attackers. Ensuring secure configurations from the outset is crucial for protecting user data and device integrity.
This advisory, ZDI-26-488, details a separate heap-based buffer overflow vulnerability within the vCardParser component of Kenwood DNR1007XR devices. Unlike the startUpdateProcess flaw, this vulnerability allows physically present attackers to execute arbitrary code on affected devices without authentication, carrying a CVSS score of 6.8. The vulnerability was reported to the vendor on February 3, 2026, and publicly disclosed on July 29, 2026, with an update to the advisory on the same day.
This new advisory, ZDI-26-487, details a local privilege escalation vulnerability in Kenwood DNR1007XR devices, specifically within the udhcpd service. The flaw stems from incorrect permissions on a resource used by the service, allowing an attacker with initial low-privilege code execution to gain root-level privileges. This is distinct from the previously reported ZDI-26-490, which involved USB permissions.