Pioneer DJ products — including every supported installation of Rekordbox, every CDJ model and more — are at risk from a severe security vulnerability that could enable an attacker to gain access to data on a laptop, desktop or USB.
The attack takes advantage of a vulnerability affecting the PRO DJ LINK function, the networking software that enables laptops, desktop computers and USBs to connect to Pioneer devices. Computers running Rekordbox as well as all PRO DJ LINK compatible gear are vulnerable to the exploit.
Pioneer DJ and AlphaTheta, Pioneer’s parent company, are not releasing many details about the vulnerability because a fix has not been deployed.
The information was only made public late Friday. Pioneer’s full list of vulnerable devices is below.

Don't Stay In
Get on our guest list for news from 5 Mag and you'll never miss a thing. It's free and we don't sell your shit.
It is not known if there have been any recorded attacks using the vulnerability to gain access to a target’s personal data. Pioneer DJ reports they have not confirmed “any cases of damage,” which is not quite the same as “no confirmed attacks.”
The vulnerability was discovered and revealed to Pioneer and AlphaTheta by DJ, producer and researcher TRIODE (Chris Le) at the DEF CON security conference on Friday. He discusses the vulnerability in more detail than has been provided by Pioneer DJ in a reel as well:
According to TRIODE, if “Link Export Mode” is enabled in Rekordbox, an attacker on the same Wi-Fi network can gain access to any file on a connected laptop or USB stick — not just music files, but any files.
Pioneer DJ claims they are still “preparing” a fix to address this vulnerability. In the meantime they suggest the following, which are wholly inadequate solutions but which we advise our readers to follow:
1. Do not plug a USB or SD card into a device using PRO DJ LINK if it contains anything other than music that you’re comfortable sharing with the entire world.
2. Do not use insecure or public Wi-Fi. Use a secure and password-protected network.
3. Update Rekordbox immediately.
Pioneer DJ says that the latest versions of Rekordbox 6 and 7 are only “partially fixed” and updating is not a permanent solution to the security threat. None of this will keep you absolutely safe, but it is hoped it will keep you safer.
You can update Rekordbox at this link from Pioneer.
HAVE YOU BEEN PWN3D?
Here is Pioneer DJ’s list of devices and software impacted by this security vulnerability. Important Note: This is their list and we have not verified the accuracy of the information. Products not listed here should not be considered “safe” — older products not listed here have likely reached the end of their lifecycle and Pioneer DJ doesn’t support them at all.
Products which are not compatible with PRO DJ LINK are not subject to the vulnerability.
DJ MODELS
⚠️ Vulnerable:
• CDJ-3000X – Fix In Progress
• CDJ-3000, -W – Fix In Progress
• CDJ-2000NXS2, -W – Fix In Progress
• CDJ-1500X – Fix In Progress
• CDJ-900NXS – Fix In Progress
• XDJ-1000MK2 – Fix In Progress
• XDJ-700 – Fix In Progress
✅ Not Affected
[ None Listed. ]
SOFTWARE
⚠️ Vulnerable:
• Rekordbox v.7 – “Partially fixed (additional updates planned). Please use Ver 7.2.17 or later.”
• Rekordbox v.6 – “Partially fixed (additional updates planned). Please use Ver 6.8.7 or later.”
• Rekordbox for iOS – Fix In Progress
• Rekordbox for Android – Fix in Progress
✅ Not Affected
• Stagehand – No Action Needed
• PRO DJ LINK Bridge – No Action Needed
ALL-IN-ONE DJ SYSTEMS
⚠️ Vulnerable:
• XDJ-AZ, -N – Fix In Progress
• XDJ-XZ – Fix In Progress
✅ Not Affected, But Being Updated:
• XDJ-AN – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• OMNIS-DUO – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• OPUS-QUAD – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• XDJ-RX3 – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• XDJ-RX2, -W – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
• XDJ-RR – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
DJ MIXERS
⚠️ Vulnerable:
[ None Listed ]
✅Not Affected
• DJM-A9 – No Action Needed
• DJM-V10 – No Action Needed
• DJM-V10-LF – No Action Needed
• DJM-V5 – No Action Needed
• DJM-900NXS2, -W – No Action Needed
OTHER PRODUCTS
✅Not Affected, But Being Updated:
• RMX-IGNITE DJ Effector – Fix In Progress – “Not affected by this vulnerability, but an update is planned in connection with security enhancements to other products”
✅Not Affected
• DJS-1000 DJ Sampler – No Action Needed
• TORAIZ TSP-16 – No Action Needed
There’s more inside 5 Mag’s member’s section — get first access to each issue for a few bucks a month.
This story has been updated to include information from TRIODE and his discovery of the vulnerability.