Blog

"Prevention is cheaper than a breach"

Home / Threats / CVE-2026-21427

CVE-2026-21427 - Stellanova APS-S301 series Plugin

CVE-2026-21427

The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running installer.

CVE-2026-21427

HIGH CVSS 8.5 Published 2026-01-08 Updated 2026-01-08
AI Risk High (76/100) Active Exploit: No strong signal Published Exploit: No public exploit references Priority: P2 Urgent
Severity Band HIGH
CVSS Vector CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Affected Components 10
Reference Links 2
AI Risk Engine High (76/100)
Exploitability High
Active Exploitation No strong signal
Published Exploit Status No public exploit references

Threat Timeline

  1. 2026-01-08 CVE published and first recorded in the threat feed.
  2. 2026-01-08 Record updated with latest vulnerability metadata.
  3. 2026-04-09 AI technical context refreshed for mitigation and impact guidance.
  4. Now Monitoring for follow-up changes, linked references, and new related CVEs.

AI Context

Machine-generated threat intelligence

AI Updated 12 days ago

AI enriched 12 days ago (2026-04-09 08:08 UTC)

Technical Summary

The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running installer.

Potential Impact

Severity is HIGH (CVSS 8.5). Depending on deployment context, affected components may be exposed to unauthorized actions or data integrity risk.

Exploitability Assessment

Exploitability is assessed as High based on severity and technical exposure profile.

Primary risk drivers: severity and technical exposure profile

Mitigation Recommendations

Validate affected product versions, prioritize patching, and monitor references for vendor remediation guidance. If immediate patching is not possible, apply compensating controls and limit exposure of vulnerable surfaces.

Detection & Monitoring

Track authentication anomalies, unexpected file writes, and suspicious plugin API activity around affected components.

Business Impact Lens

Prioritize remediation where affected components process customer data, admin sessions, or Internet-exposed workflows.

Affected Products

Stellanova APS-S301 series PLUGIN · stellanova-aps-s301-series Affected: >= allversions, <= allversions Fixed version not specified
Stellanova Limited APS-S202J-LM PLUGIN · stellanova-limited-aps-s202j-lm Affected: >= allversions, <= allversions Fixed version not specified
Stellanova Lite APS-S201JGL PLUGIN · stellanova-lite-aps-s201jgl Affected: >= allversions, <= allversions Fixed version not specified
Stellanova Lite APS-S201JGR PLUGIN · stellanova-lite-aps-s201jgr Affected: >= allversions, <= allversions Fixed version not specified
Stellanova Lite APS-S201JR PLUGIN · stellanova-lite-aps-s201jr Affected: >= allversions, <= allversions Fixed version not specified
Stellanova Lite APS-S201JS PLUGIN · stellanova-lite-aps-s201js Affected: >= allversions, <= allversions Fixed version not specified
USB DAC Amplifier APS-DA101JGL PLUGIN · usb-dac-amplifier-aps-da101jgl Affected: >= allversions, <= allversions Fixed version not specified
USB DAC Amplifier APS-DA101JGR PLUGIN · usb-dac-amplifier-aps-da101jgr Affected: >= allversions, <= allversions Fixed version not specified
USB DAC Amplifier APS-DA101JR PLUGIN · usb-dac-amplifier-aps-da101jr Affected: >= allversions, <= allversions Fixed version not specified
USB DAC Amplifier APS-DA101JS PLUGIN · usb-dac-amplifier-aps-da101js Affected: >= allversions, <= allversions Fixed version not specified
Scroll to top