AlphaTheta has published a notice warning of a security vulnerability in Pro DJ Link, the network protocol that ties Rekordbox and CDJ/XDJ players together.
According to the company, a third party who gains unauthorised access to a Pro DJ Link network could view data stored on a connected Windows PC or Mac, or on USB and SD cards plugged into a CDJ or XDJ on that network. Technical details are being withheld until a fix is available, and AlphaTheta says it has had no reports of anyone actually being affected so far.
Good on them for saying something at all – plenty of companies would have quietly patched this and kept quiet. Less good is that they’ve buried the list of which gear is affected in a PDF two steps away from the notice rather than in the notice itself, so most DJs reading the announcement will come away with no idea whether their own kit is on the list.
For the record, the affected players are the CDJ-3000X, CDJ-3000, CDJ-2000NXS2, CDJ-1500X, CDJ-900NXS, XDJ-1000MK2 and XDJ-700, plus the XDJ-AZ and XDJ-XZ all-in-ones, and Rekordbox for iOS and Android. Mixers are in the clear. Fixes for the players are listed as in progress.
What to do about it
Update Rekordbox to 7.2.17 or later, or 6.8.7 or later, both of which are partly patched already. Avoid using USB or SD cards with anything sensitive on them when you’re playing on a linked set-up. And if your player is on a Wi-Fi network, make sure that network has a password.
Beyond that, there’s not much to worry about. If you’re DJing at home or at small gigs, the chances of someone getting onto your network to go rummaging through your files are slim. We’ll let you know when the firmware updates land.


