HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Critical Code‑Execution Flaw in Kenwood DNR1007XR Firmware Update (CVE‑2026‑18267) Threatens On‑Prem Radio Devices

A link‑following bug in Kenwood’s DNR1007XR radios lets a physically present attacker execute arbitrary code as root. The flaw highlights the need for SOC 2‑aligned firmware‑patch processes and continuous evidence of device hardening.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Critical Code‑Execution Flaw in Kenwood DNR1007XR Firmware Update (CVE‑2026‑18267) Threatens On‑Prem Radio Devices

What It Is – A link‑following vulnerability in the firmware‑update routine of Kenwood’s DNR1007XR two‑way radio allows an attacker with physical access to place a symbolic link, causing the service to write a file anywhere on the system and execute it as root.

Exploitability – No authentication is required; the flaw can be triggered locally with low effort. A proof‑of‑concept was demonstrated at Pwn2Own. CVSS 6.8 (AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).

Affected Products – Kenwood DNR1007XR radios (firmware versions prior to the 2020‑2020f update).

Why It Matters for Compliance & Audit Readiness

  • Control Mapping – The issue maps directly to SOC 2 CC6.1 (Change Management) and CC7.1 (System Operations); auditors will expect documented evidence that firmware patches are applied promptly.
  • Continuous Evidence – Demonstrating a repeatable process for validating firmware integrity provides audit‑ready proof that the organization mitigates “unauthorized code execution” risks.
  • Enterprise Procurement – Many public‑safety and telecom buyers now require proof of SOC 2‑aligned device‑hardening before awarding contracts.

Recommended Actions

  • Deploy Kenwood’s 2020‑2020f firmware update immediately on all DNR1007XR units.
  • Verify firmware signatures after installation and retain hash logs as immutable evidence.
  • Map the patch‑process to SOC 2 CC6.1/CC7.1 controls in your compliance framework and capture the change‑request, approval, and verification artifacts in a centralized repository.
  • Institute continuous monitoring for unauthorized firmware modifications (e.g., file‑integrity monitoring) and integrate the alerts into your audit‑ready evidence pipeline.

Source: Zero Day Initiative advisory ZDI‑26‑484

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-484/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →