Pioneer DJ Warns of Major Security Threat to Rekordbox & Every CDJ - 5 Magazine
News
Tracks
Features
Mixes
Events
Genres
Acid House
Ambient Music
Balearica
Deep House
Disco/Edits
Electronica
Garage House
Soulful House
Synth
Tech House
Techno
UK Garage
Login
Search
Members Login
Become A Member
Advertise
About 5 Mag
Submit Music
Contact Us
5 Magazine
News
Tracks
Features
Mixes
Events
Genres
Acid House
Ambient Music
Balearica
Deep House
Disco/Edits
Electronica
Garage House
Soulful House
Synth
Tech House
Techno
UK Garage
Login
Share
Telegram
Pioneer DJ products — including every supported installation of Rekordbox, every CDJ model and more — are at risk from a severe security vulnerability that could enable an attacker to gain access to data on a laptop, desktop or USB.
The attack takes advantage of a vulnerability affecting the PRO DJ LINK function, the networking software that enables laptops, desktop computers and USBs to connect to Pioneer devices.
Pioneer DJ and AlphaTheta, Pioneer’s parent company, are not releasing many details about the vulnerability because a fix has not been deployed. From their description it appears that an attacker can gain "read-only access" to laptops and USBs, which would be a serious exploit on a targeted laptop.
The information was only made public late Friday. Pioneer’s full list of vulnerable devices is below.
It is not known if there have been any recorded attacks using the vulnerability to gain access to a target’s personal data. Pioneer DJ reports they have not confirmed "any cases of damage," which is not quite the same as "no confirmed attacks." They also have not revealed how they came across the security threat — whether it was reported by a white hat hacker, discovered by their own team or observed from an attack in the wild.
Don't Stay In
Get on our guest list for news from 5 Mag and you'll never miss a thing. It's free and we don't sell your shit.
SUBSCRIBE
Pioneer DJ claims they are still "preparing" a fix to address this vulnerability. In the meantime they suggest the following, which are wholly inadequate solutions but which we advise our readers to follow:
1. Do not plug a USB or SD card into a device using PRO DJ LINK if it contains anything other than music that you’re comfortable sharing with the entire world.
2. Do not use insecure or public Wi-Fi. Use a secure and password-protected network.
3. Update Rekordbox immediately.
But Pioneer DJ admits that the latest versions of Rekordbox 6 and 7 are only "partially fixed" and updating is not a permanent solution to the security threat. None of this will keep you absolutely safe, but it is hoped it will keep you safer.
You can update Rekordbox at this link from Pioneer.
HAVE YOU BEEN PWN3D?
Here is Pioneer DJ’s list of devices and software impacted by this security vulnerability. Important Note: This is their list and we have not verified the accuracy of the information. Products not listed here are not "safe" — older products not listed here have likely reached the end of their lifecycle and Pioneer DJ doesn’t support them at all.
DJ MODELS
⚠️ Vulnerable:
• CDJ-3000X – Fix In Progress
• CDJ-3000, -W – Fix In Progress
• CDJ-2000NXS2, -W – Fix In Progress
• CDJ-1500X – Fix In Progress
• CDJ-900NXS – Fix In Progress
• XDJ-1000MK2 – Fix In Progress
• XDJ-700 – Fix In Progress
✅ Not Affected
[ None Listed. ]
SOFTWARE
⚠️ Vulnerable:
• Rekordbox v.7 – "Partially fixed (additional updates planned). Please use Ver 7.2.17 or later."
• Rekordbox v.6 – "Partially fixed (additional updates planned). Please use Ver 6.8.7 or later."
• Rekordbox for iOS – Fix In Progress
• Rekordbox for Android – Fix in Progress
✅ Not Affected
• Stagehand – No Action Needed
• PRO DJ LINK Bridge – No Action Needed
ALL-IN-ONE DJ SYSTEMS
⚠️ Vulnerable:
• XDJ-AZ, -N – Fix In Progress
• XDJ-XZ – Fix In Progress
✅ Not Affected, But Being Updated:
• XDJ-AN – Fix In Progress – "Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products"
• OMNIS-DUO – Fix In Progress – "Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products"
• OPUS-QUAD – Fix In Progress – "Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products"
• XDJ-RX3 – Fix In Progress – "Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products"
• XDJ-RX2, -W – Fix In Progress – "Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products"
• XDJ-RR – Fix In Progress – "Not affected by this vulnerability, but an update is planned in...