Security Vulnerability Discovered in rekordbox and CDJ/XDJ Devices
DJs are urged to update their rekordbox and CDJ/XDJ devices following a security vulnerability discovery related to PRO DJ LINK.

Key Takeaways
- Security vulnerability discovered in rekordbox and CDJ/XDJ devices.
- Unauthorized access can allow viewing of files on connected devices.
- DJs are advised to update firmware and software immediately.
DJs using rekordbox software and various CDJ and XDJ models are being advised to urgently update their systems following the identification of a security vulnerability associated with AlphaTheta's PRO DJ LINK. This vulnerability could allow unauthorized individuals, with access to the same network as the PRO DJ LINK, to view files stored on connected devices, including USB drives, SD cards in the CDJs and XDJs, as well as data on computers running rekordbox. It is essential to note that this issue does not arise from internet-based attacks but rather from intrusions within the specific DJ network utilized.
The PRO DJ LINK technology provides a networking option that facilitates communication between compatible DJ equipment and rekordbox over wired or wireless networks. This allows DJs to access their music libraries and share performance data seamlessly during their sets. Unfortunately, the very capabilities enabling this streamlined connectivity also position it as a target for potential breaches, as highlighted by the recent findings.
The discovery was made by security researcher Chris L., also known as Triode, who reported it to AlphaTheta while investigating the PRO DJ LINK protocol. Triode explained that the vulnerability stems from the use of an NFS server to transfer music files. Through this exploited vulnerability, an attacker may request files that would not typically be shared through the DJ system, thereby compromising the privacy and security of the DJ's music collection.
AlphaTheta has outlined a list of affected products to ensure users can address this issue promptly. The vulnerable hardware includes popular models such as the XDJ-700, XDJ-1000MK2, CDJ-900NXS2, CDJ-2000NXS2, CDJ-3000, and CDJ-3000X. Additionally, several all-in-one systems, including the OMNIS-DUO, XDJ-RX2, XDJ-RX3, XDJ-RR, and XDJ-XZ, are also impacted. Notably, the firmware and software versions of rekordbox 6 and 7 for both Windows and macOS, along with the mobile versions for iOS and Android, are vulnerable.
It is important to clarify that DJM mixers and other related products, such as Stagehand and PRO DJ LINK Bridge, are not a part of this vulnerability. Users are encouraged to apply updates as soon as possible to safeguard their equipment and data against potential threats stemming from this issue.
Frequently Asked Questions
What is the PRO DJ LINK vulnerability?
It allows unauthorized users on the same network to access and view files on connected devices.
Which devices are affected by this vulnerability?
Affected models include XDJ-700, CDJ-900NXS2, CDJ-2000NXS2, and several others.
Source: Gear & Tech
- EDM
- DJ Tech
- Cybersecurity

Riley Park
Industry Analyst
Riley writes about labels, platforms, music tech, and the business side of electronic music.
Comments (0)
No comments yet. Be the first to comment!
