CVE-2025-8643 Kenwood DMX958XR Firmware Update Command Injection Vulnerability

CVE Details

Basic Information

Title CVE-2025-8643 Kenwood DMX958XR Firmware Update Command Injection Vulnerability
Type cve
Published 2025-08-06T01:17:57
Last Seen 2025-08-06T01:49:26
Modified 2025-08-06T01:17:57

CVSS Information

Base Score 6.8 (MEDIUM)
Attack Vector CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

AI Analysis

AI Description This vulnerability allows attackers with physical access to execute arbitrary code on Kenwood DMX958XR devices. It does not require authentication, making it easier to exploit. The vulnerability is related to the firmware update process.
AI Severity Medium
AI Vendor Kenwood Electronics
AI Product Kenwood DMX958XR

Additional Information

CVE List CVE-2025-8643
CWE List CWE-78
Bulletin Family cve

Description

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit…

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.