CVE Details
Basic Information
| Title | CVE-2025-8638 Kenwood DMX958XR Firmware Update Command Injection Vulnerability |
|---|---|
| Type | cve |
| Published | 2025-08-06T01:17:36 |
| Last Seen | 2025-08-06T01:49:26 |
| Modified | 2025-08-06T01:17:36 |
CVSS Information
| Base Score | 6.8 (MEDIUM) |
|---|---|
| Attack Vector | CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
AI Analysis
| AI Description | A vulnerability in the Kenwood DMX958XR firmware update allows physically present attackers to execute arbitrary code without authentication, potentially leading to system compromise. |
|---|---|
| AI Severity | Medium |
| AI Vendor | JVCKenwood |
| AI Product | Kenwood DMX958XR |
| AI Version | Versions not specified |
Additional Information
| CVE List | CVE-2025-8638 |
|---|---|
| CWE List | CWE-78 |
| Bulletin Family | cve |
Description
Kenwood DMX958XR Firmware Update Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Kenwood DMX958XR devices. Authentication is not required to exploit…