Published:2026/01/08  Last Updated:2026/01/08

JVN#17956874
The installers for multiple PIONEER products may insecurely load Dynamic Link Libraries

Overview

The installers for multiple products provided by PIONEER CORPORATION may insecurely load Dynamic Link Libraries.

Products Affected

The driver software for the following products is affected by this vulnerability:

  • USB DAC Amplifier
    • APS-DA101JS
    • APS-DA101JR
    • APS-DA101JGL
    • APS-DA101JGR
  • Stellanova Lite
    • APS-S201JS
    • APS-S201JR
    • APS-S201JGL
    • APS-S201JGR
  • Stelllanova Limited
    • APS-S202J-LM
  • Stelllanova
    • APS-S301 Series

Description

The installers for multiple products provided by PIONEER CORPORATION contain the following vulnerability.

  • Uncontrolled search path element (CWE-427)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.5
    • CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Base Score 7.8
    • CVE-2026-21427

Impact

Arbitrary code may be executed with the privileges of the running installer.

Solution

Contact the developer
Contact the developer for mitigations. For more information, see [Vendor Status] section below.

Vendor Status

Vendor Status Last Update Vendor Notes
PIONEER CORPORATION Vulnerable 2026/01/08 PIONEER CORPORATION website

References

  1. Japan Vulnerability Notes JVNTA#91240916
    Insecure DLL Loading and Command Execution Issues on Many Windows Application Programs

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-21427
JVN iPedia JVNDB-2026-000004