Browse all 36 CVE security advisories affecting Kenwood. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Kenwood Corporation manufactures consumer electronics, automotive audio systems, and professional communication equipment, primarily serving retail and commercial markets. Security audits reveal a significant vulnerability footprint, with twenty-nine Common Vulnerabilities and Exposures (CVEs) currently documented. These flaws predominantly involve remote code execution and cross-site scripting, often stemming from insecure web interfaces embedded in networked devices. Privilege escalation vulnerabilities also appear frequently, allowing unauthorized users to gain administrative control over affected hardware. Notable incidents include the exploitation of default credentials in older IP cameras and radios, which facilitated unauthorized access to sensitive audio feeds and system configurations. The company has issued firmware updates to patch critical remote code execution paths, yet legacy devices remain exposed due to limited support lifecycles. This pattern highlights a recurring challenge in integrating complex web functionalities into embedded IoT ecosystems without rigorous security-by-design principles.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-18273 | Kenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation Vulnerability — DNR1007XR CWE-276 | - | - | 2026-08-20 |
| CVE-2026-18272 | Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability — DNR1007XR CWE-78 | - | - | 2026-08-20 |
| CVE-2026-18271 | Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability — DNR1007XR CWE-122 | - | - | 2026-08-20 |
| CVE-2026-18270 | Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability — DNR1007XR CWE-732 | - | - | 2026-08-20 |
| CVE-2026-18269 | Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability — DNR1007XR CWE-787 | - | - | 2026-08-20 |
| CVE-2026-18268 | Kenwood DNR1007XR JKGenService Command Injection Local Privilege Escalation Vulnerability — DNR1007XR CWE-78 | - | - | 2026-08-20 |
| CVE-2026-18267 | Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability — DNR1007XR CWE-59 | - | - | 2026-08-20 |
This page lists every published CVE security advisory associated with Kenwood. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.