CVE-2025-8640 Kenwood DMX958XR Firmware Update Command Injection Vulnerability

CVE Details

Basic Information

Title CVE-2025-8640 Kenwood DMX958XR Firmware Update Command Injection Vulnerability
Type cve
Published 2025-08-06T01:17:43
Last Seen 2025-08-06T01:49:26
Modified 2025-08-06T01:17:43

CVSS Information

Base Score 6.8 (MEDIUM)
Attack Vector CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Confidentiality Impact HIGH
Integrity Impact HIGH
Availability Impact HIGH

AI Analysis

AI Description This vulnerability allows physically present attackers to execute arbitrary code on Kenwood DMX958XR devices without requiring authentication. It is a command injection flaw in the firmware update process.
AI Severity Medium
AI Vendor Kenwood
AI Product Kenwood DMX958XR
AI Version Unspecified

Additional Information

CVE List CVE-2025-8640
CWE List CWE-78
Bulletin Family cve

Description

Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit…

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.