AlphaTheta Discloses Security Vulnerability In rekordbox and CDJ Models

Pioneer DJ’s parent company AlphaTheta has disclosed a security vulnerability in PRO DJ LINK, the networking protocol that connects CDJs, XDJs and rekordbox software.The vulnerability could let an unauthorized user on the same network view files stored on a DJ’s computer or on a USB or SD card plugged into an affected player.
Ad 0:00 Click for sound 0:00 / 0:00 The company said it has not confirmed any cases of actual damage from the flaw, but urged users to update rekordbox to the latest version, avoid loading sensitive files onto USB or SD cards used with PRO DJ LINK, and connect players only to secure, password-protected networks.The vulnerability was first reported by Triode, a San Francisco-based DJ, producer and developer.
According to his explanation, PRO DJ LINK relies on a Network File System server that starts automatically, on rekordbox when Link Export mode is enabled, and on hardware like the CDJ-3000 as soon as the unit boots.That server can be pointed at any file path on the connected device, and its authentication uses a fixed value rather than a unique password, effectively leaving it open to anyone on the network, according to our friends at CDM.
Affected hardware includes the CDJ-3000X, CDJ-3000, CDJ-2000NXS2, CDJ-1500X, CDJ-900NXS, XDJ-1000MK2, XDJ-700, and the XDJ-AZ and XDJ-XZ all-in-ones.DJM mixers are not affected.
Rekordbox versions 7.2.17 and 6.8.7 include partial fixes, while the iOS and Android apps are still awaiting patches.Notably, the risk only applies to networked setups.
DJs syncing gear over a closed, offline connection, or loading music via USB without Wi-Fi involved, are not exposed.The danger surfaces specifically at venues running PRO DJ LINK over open or unsecured Wi-Fi, rather than a private, password-protected network.
You can read AlphaTheta’s official announcement and download firmware updates here....