AlphaTheta Says Security Vulnerability Found In Rekordbox PRO DJ LINK

AlphaTheta has announced an unpatched security vulnerability affecting the PRO DJ LINK function in rekordbox and certain CDJ/XDJ DJ players.
The company says the flaw could allow someone who gains unauthorized access to a PRO DJ LINK network to view data stored on a connected Windows PC or Mac, as well as data on USB or SD cards inserted into connected DJ players.
What does this mean in practical terms?
AlphaTheta says that this does not mean that a CDJ or XDJ player can suddenly be hacked simply because it is turned on. The potential problem arises when the player is connected to a PRO DJ LINK network and an unauthorized person is able to get onto that network. If that happens, the vulnerability could potentially give that person access to files and other data that the DJ has made available through the connected equipment.
For DJs, the main concern is therefore what data is connected to the DJ network, rather than the music player itself being physically damaged. AlphaTheta recommends updating rekordbox 6 or 7 and its iOS/Android apps to the latest versions, avoiding USB drives and SD cards containing sensitive information when using PRO DJ LINK, and using a secure, password-protected Wi-Fi network when connecting players wirelessly.
AlphaTheta says it has not confirmed any cases of damage resulting from the vulnerability and is withholding technical details until a fix is available. The company is currently preparing an update and says it will provide further information as its response progresses.























