HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Local Privilege Escalation (CVE‑2026‑18273) in Kenwood DNR1007XR USB Mount Permissions Risks Physical Attackers

Kenwood’s DNR1007XR radio contains a CVE‑2026‑18273 flaw that lets a physically present attacker elevate a low‑privilege process to root via incorrect USB mount permissions. The issue highlights a control‑mapping gap that SOC 2 auditors will scrutinize when evaluating hardware‑security controls.

LiveThreat™ Intelligence · 📅 July 30, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

Local Privilege Escalation (CVE‑2026‑18273) in Kenwood DNR1007XR USB Mount Permissions Risks Physical Attackers

What It Is — A zero‑day flaw (CVE‑2026‑18273) in the Kenwood DNR1007XR radio’s USB filesystem mount point grants locally‑executed, low‑privilege code the ability to read‑write a privileged directory, enabling root‑level code execution.

Exploitability — Requires physical proximity and initial low‑privilege code execution; CVSS 6.6 (AV:P, AC:L, PR:L, UI:N, S:U, C:H, I:H, A:H). No public exploit code, but the vulnerability is fully disclosed and a vendor patch is available.

Affected Products — Kenwood DNR1007XR (firmware 2020 F).

Why It Matters for Compliance & Audit Readiness

  • Demonstrates a control‑mapping gap: default OS permissions were not aligned with the organization’s least‑privilege policy, a SOC 2 CC6.1 (Logical Access) requirement.
  • Continuous evidence of configuration hardening (e.g., immutable mount options) is now a critical audit artifact for any environment that includes third‑party communication hardware.
  • Enterprise buyers increasingly demand proof that such hardware is covered by a documented, monitored configuration‑management process—failure to do so can stall contracts or trigger remediation clauses.

Recommended Actions

  • Deploy Kenwood’s firmware update immediately and verify the corrected mount permissions.
  • Update your configuration‑management database (CMDB) to reflect the new baseline and map the change to the SOC 2 CC6.1 control.
  • Implement automated monitoring (e.g., file‑integrity or permission‑drift tools) to capture continuous evidence of the mount‑point state.
  • Document the incident response and remediation steps in your audit evidence repository.

Source: Zero Day Initiative advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-490/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Misconfigurations are control gaps in disguise.

Verisq AI Trust Operations turns findings like this into mapped controls with continuous evidence, keeping your audit readiness current instead of point-in-time.

Map your controls with Verisq AI Trust Operations →