AlphaTheta warns of security vulnerability affecting PRO DJ LINK in rekordbox and certain CDJ and XDJ models
The company said it has not confirmed any cases of damage resulting from the vulnerability to date
AlphaTheta, the company behind Pioneer DJ, has disclosed a security vulnerability affecting the PRO DJ LINK function in rekordbox and certain CDJ and XDJ models.
The vulnerability could allow an unauthorised third party who gains access to a PRO DJ LINK network to view data stored on a Windows PC or Mac, as well as data contained on USB or SD cards inserted into a connected CDJ or XDJ unit.
The company said in a statement released over the weekend that it has withheld technical details of the vulnerability for now in order to prevent potential misuse while a fix is being prepared. No cases of damage resulting from the vulnerability have been confirmed to date.
AlphaTheta is advising users to update rekordbox on desktop and mobile devices to the latest available version, including versions 7 and 6 on desktop and iOS and Android devices. Users operating PRO DJ LINK are also being asked to avoid connecting USB or SD cards containing sensitive data to their CDJ or XDJ equipment.
Those connecting players to a Wi-Fi network are advised to use a secure, password-protected connection. The company is currently working on a fix and says further updates will be published as they become available.
