CVE-2025-8654
8.8Kenwood · DMX958XR
Kenwood DMX958XR is vulnerable to OS command injection in the ReadMVGImage function, allowing unauthenticated network-adjacent attackers to achieve remote code execution as root.
Executive summary
A critical command injection vulnerability in the Kenwood DMX958XR allows unauthenticated network-adjacent attackers to achieve full system compromise with root privileges.
Vulnerability
The flaw exists within the ReadMVGImage function, where insufficient validation of user-supplied input leads to OS command injection. This vulnerability is exploitable by an unauthenticated attacker positioned on the local network.
Business impact
The ability for an unauthenticated attacker to execute arbitrary commands with root privileges poses a catastrophic risk to device integrity and network security. Successful exploitation could lead to total system takeover, lateral movement within the connected network environment, and persistent unauthorized access. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that requires immediate prioritization.
Remediation
Immediate Action: Monitor for official firmware updates from Kenwood and apply them immediately upon release. As a patch is currently unknown, restrict network access to affected devices to trusted subnets only.
Proactive Monitoring: Inspect network traffic for anomalous command patterns directed at the device and monitor system logs for signs of unauthorized process execution or unexpected root-level activity.
Compensating Controls: Utilize network segmentation to isolate the DMX958XR from critical infrastructure and ensure it is not reachable from the public internet or untrusted network segments.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full system compromise via root-level command injection, administrators must treat this vulnerability with extreme urgency. Isolate affected Kenwood DMX958XR units from production networks immediately and maintain a strict posture of least privilege until a vendor-supplied firmware patch is verified and deployed.