CVE-2026-21427

HIGH

Pioneer Corporation - DLL Hijacking

Title source: llm
STIX 2.1

Description

The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running installer.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 0.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (10)
PIONEER CORPORATION/Stellanova APS-S301 series all versions
PIONEER CORPORATION/Stellanova Limited APS-S202J-LM all versions
PIONEER CORPORATION/Stellanova Lite APS-S201JGL all versions
PIONEER CORPORATION/Stellanova Lite APS-S201JGR all versions
PIONEER CORPORATION/Stellanova Lite APS-S201JR all versions
PIONEER CORPORATION/Stellanova Lite APS-S201JS all versions
PIONEER CORPORATION/USB DAC Amplifier APS-DA101JGL all versions
PIONEER CORPORATION/USB DAC Amplifier APS-DA101JGR all versions
PIONEER CORPORATION/USB DAC Amplifier APS-DA101JR all versions
PIONEER CORPORATION/USB DAC Amplifier APS-DA101JS all versions
Published Jan 08, 2026
Tracked Since Feb 18, 2026