CVE-2025-5834CWE-1326

Pioneer DMH-WT7600NEX Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability

Medium · published June 25, 2025

CVSS v3.0
4.4
EPSS
0%
Percentile
14.6
In the wild
Unconfirmed
What it is

Pioneer DMH-WT7600NEX Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to bypass authentication on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.

The specific flaw exists within the configuration of the application system-on-chip (SoC). The issue results from the lack of a properly configured hardware root of trust. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the boot process. Was ZDI-CAN-26078.

The record
Technical detail
CVSS v3.0
4.4 · MEDIUM
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0
Not supplied
EPSS
0.00237 · 14.6th percentile
Weakness
CWE-1326 · Missing Immutable Root of Trust in Hardware
Published
2025-06-25T17:58Z
EPSS history
Timeline
  • 25 JUN 17:58Z
    Pioneer DMH-WT7600NEX Missing Immutable Root of Trust in Hardware Local Privilege Escalation Vulnerability
    cvelistv5