Looking at the Attack Surfaces of the Kenwood DMX958XR IVI
ID: db8eac1f-c2f6-525d-b2c4-2f092b9f077c
STIX ID: report--db8eac1f-c2f6-525d-b2c4-2f092b9f077c
Feed Name: Zero Day Initiative (ZDI) Blog
This post maps the attack surface of the Kenwood DMX958XR IVI head unit, detailing vectors such as USB media parsing (multiple audio/video formats and filesystems), Bluetooth profiles/codecs, and a Wi‑Fi access point with services on TCP 7000/8086 and UDP 67/5353/35917/50002/60794. It highlights potential risk areas in Android Auto/Apple CarPlay connectivity and Kenwood’s Portal and Remote S apps (e.g., image handling and data persistence). The article provides an extensive list of open-source components present on the device and encourages further vulnerability research, noting no recent Pwn2Own head‑unit compromises via Android Auto/CarPlay and previewing a forthcoming firmware deep dive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
