Local Privilege Escalation (CVE‑2026‑18273) in Kenwood DNR1007XR USB Mount Permissions Risks Physical Attackers
What It Is — A zero‑day flaw (CVE‑2026‑18273) in the Kenwood DNR1007XR radio’s USB filesystem mount point grants locally‑executed, low‑privilege code the ability to read‑write a privileged directory, enabling root‑level code execution.
Exploitability — Requires physical proximity and initial low‑privilege code execution; CVSS 6.6 (AV:P, AC:L, PR:L, UI:N, S:U, C:H, I:H, A:H). No public exploit code, but the vulnerability is fully disclosed and a vendor patch is available.
Affected Products — Kenwood DNR1007XR (firmware 2020 F).
Why It Matters for Compliance & Audit Readiness
- Demonstrates a control‑mapping gap: default OS permissions were not aligned with the organization’s least‑privilege policy, a SOC 2 CC6.1 (Logical Access) requirement.
- Continuous evidence of configuration hardening (e.g., immutable mount options) is now a critical audit artifact for any environment that includes third‑party communication hardware.
- Enterprise buyers increasingly demand proof that such hardware is covered by a documented, monitored configuration‑management process—failure to do so can stall contracts or trigger remediation clauses.
Recommended Actions
- Deploy Kenwood’s firmware update immediately and verify the corrected mount permissions.
- Update your configuration‑management database (CMDB) to reflect the new baseline and map the change to the SOC 2 CC6.1 control.
- Implement automated monitoring (e.g., file‑integrity or permission‑drift tools) to capture continuous evidence of the mount‑point state.
- Document the incident response and remediation steps in your audit evidence repository.
Source: Zero Day Initiative advisory