Pioneer DJ products — including every supported installation of Rekordbox, every CDJ model and more — are at risk from a severe security vulnerability that could enable an attacker to gain access to data on a laptop, desktop or USB.

The attack takes advantage of a vulnerability affecting the PRO DJ LINK function, the networking software that enables laptops, desktop computers and USBs to connect to Pioneer devices.

Pioneer DJ and AlphaTheta, Pioneer’s parent company, are not releasing many details about the vulnerability because a fix has not been deployed. From their description it appears that an attacker can gain “read-only access” to laptops and USBs, which would be a serious exploit on a targeted laptop.

The information was only made public late Friday. Pioneer’s full list of vulnerable devices is below.

It is not known if there have been any recorded attacks using the vulnerability to gain access to a target’s personal data. Pioneer DJ reports they have not confirmed “any cases of damage,” which is not quite the same as “no confirmed attacks.” They also have not revealed how they came across the security threat — whether it was reported by a white hat hacker, discovered by their own team or observed from an attack in the wild.

Don't Stay In 💌

Get on our guest list for news from 5 Mag and you'll never miss a thing. It's free and we don't sell your shit. ✅

Pioneer DJ claims they are still “preparing” a fix to address this vulnerability. In the meantime they suggest the following, which are wholly inadequate solutions but which we advise our readers to follow:

1. Do not plug a USB or SD card into a device using PRO DJ LINK if it contains anything other than music that you’re comfortable sharing with the entire world.
2. Do not use insecure or public Wi-Fi. Use a secure and password-protected network.
3. Update Rekordbox immediately.

 

But Pioneer DJ admits that the latest versions of Rekordbox 6 and 7 are only “partially fixed” and updating is not a permanent solution to the security threat. None of this will keep you absolutely safe, but it is hoped it will keep you safer.

You can update Rekordbox at this link from Pioneer.

 

HAVE YOU BEEN PWN3D?

Here is Pioneer DJ’s list of devices and software impacted by this security vulnerability. Important Note: This is their list and we have not verified the accuracy of the information. Products not listed here are not “safe” — older products not listed here have likely reached the end of their lifecycle and Pioneer DJ doesn’t support them at all.

DJ MODELS

⚠️ Vulnerable:
• CDJ-3000X – Fix In Progress
CDJ-3000, -W – Fix In Progress
• CDJ-2000NXS2, -W – Fix In Progress
• CDJ-1500X – Fix In Progress
• CDJ-900NXS – Fix In Progress
• XDJ-1000MK2 – Fix In Progress
• XDJ-700 – Fix In Progress

✅ Not Affected
[ None Listed. Every DJ model is currently vulnerable. ]

 

SOFTWARE

⚠️ Vulnerable:
• Rekordbox v.7 – “Partially fixed (additional updates planned). Please use Ver 7.2.17 or later.”
• Rekordbox v.6 – “Partially fixed (additional updates planned). Please use Ver 6.8.7 or later.”
• Rekordbox for iOS – Fix In Progress
• Rekordbox for Android – Fix in Progress

✅ Not Affected
• Stagehand – No Action Needed
• PRO DJ LINK Bridge – No Action Needed

 

ALL-IN-ONE DJ SYSTEMS

⚠️ Vulnerable:
• XDJ-AZ, -N – Fix In Progress
• XDJ-XZ – Fix In Progress

✅ Not Affected, But Being Updated:
• XDJ-AN – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• OMNIS-DUO – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• OPUS-QUAD – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• XDJ-RX3 – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• XDJ-RX2, -W – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• XDJ-RR – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”

 

DJ MIXERS

⚠️ Vulnerable:
[ None Listed ]

✅Not Affected
• DJM-A9 – No Action Needed
• DJM-V10 – No Action Needed
• DJM-V10-LF – No Action Needed
• DJM-V5 – No Action Needed
• DJM-900NXS2, -W – No Action Needed

 

OTHER PRODUCTS

✅Not Affected, But Being Updated:
• RMX-IGNITE DJ Effector – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”

✅Not Affected
• DJS-1000 DJ Sampler – No Action Needed
• TORAIZ TSP-16 – No Action Needed

There’s more inside 5 Mag’s member’s section — get first access to each issue for a few bucks a month.