HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Out-of-Bounds Write (CVE-2026-18269) Enables Unauthenticated Code Execution on Kenwood DNR1007XR Devices

Kenwood’s DNR1007XR two‑way radio contains a buffer‑write flaw (CVE‑2026‑18269) that lets a physically present attacker execute arbitrary code as root (CVSS 6.8). For SOC 2‑compliant organizations, the lack of authentication underscores gaps in access‑control and patch‑management processes.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
zerodayinitiative.com

Out-of-Bounds Write (CVE‑2026‑18269) Enables Unauthenticated Code Execution on Kenwood DNR1007XR Devices

What It Is — A buffer‑write flaw in the tchdr_bytestream_read function of Kenwood’s DNR1007XR two‑way radio allows an attacker who is physically present to write past the end of an allocated buffer and execute arbitrary code with root privileges.

Exploitability — No authentication is required; the vulnerability is publicly disclosed (CVSS 6.8, AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H). No public exploit code has been released, but the proof‑of‑concept demonstrated at Pwn2Own shows the attack is practical.

Affected Products — Kenwood DNR1007XR (firmware 2020 F).

Why It Matters for Compliance & Audit Readiness

  • SOC 2 Access‑Control (CC6.1) — The flaw bypasses authentication, highlighting the need for documented logical and physical access controls and evidence that only authorized personnel can interact with critical devices.
  • Continuous Monitoring — Detecting unauthorized firmware changes or anomalous device behavior is essential evidence for audit readiness.
  • Patch Management Evidence — Maintaining a verifiable patch‑deployment record satisfies the “Change Management” and “System Operations” criteria of SOC 2.

Recommended Actions

  • Deploy Kenwood’s firmware update immediately and verify the version on every DNR1007XR unit.
  • Update your asset inventory to tag the radios as “high‑risk firmware‑managed devices” and map them to SOC 2 CC6.1 (Logical Access Control) and CC7.1 (System Operations).
  • Enable continuous integrity monitoring (e.g., checksum verification) to capture any future unauthorized firmware modifications.
  • Document the remediation steps in your compliance evidence repository for the next audit cycle.

Source: Zero Day Initiative advisory ZDI‑26‑486

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-486/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →