CVE-2026-18270
Kenwood DNR1007XR udhcpd Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Kenwood DNR1007XR devices. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the udhcpd service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of root. Was ZDI-CAN-29111.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.12%
- CWE
- CWE-732
- Published
- 2026-08-20
- Last modified
- 2026-08-26
Affected products
- Kenwood DNR1007XR
Weakness type
Related vulnerabilities
- CVE-2026-84828 — Pcs: pcs: non-root haclient users can read arbitrary files via pcs host auth --token
- CVE-2026-19583 — Velociraptor Required Permissions bypass by using client monitoring queries
- CVE-2026-79617 — Improper Access Control Leading to Display Exposure in TÜBİTAK BİLGEM's Pardus LightDM Greeter
- CVE-2026-80054 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-82312 — OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated...
- CVE-2026-80112 — PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control via DirectIo64.sys
- CVE-2021-43613 — SysPasswordDxe: Password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
- CVE-2026-78604 — Incorrect Permission Assignment for Critical Resource in Elastic Agent Leading to Local Privilege Escalation to SYSTEM