Rekordbox is one of the worst pieces of software I have to interact with regularly, and it reminds me of others descriptions of IoT software/firmware.
"PRO DJ LINK" enables you to access rekordbox libraries (and load music files) remotely from other devices, whether that be on a computer or dedicated Pioneer/AlphaTheta hardware.
The vulnerability in question requires the attacker to be on the same local network as the instance of rekordbox and for the remote library feature to be enabled. Interested in the full writeup once it's released
I too also have a special place of hate for Rekordbox. However I'm somewhat confused by this vulnerability, isn't plug n play unauthenticated file access essentially a core feature of "PRO DJ LINK"? The security mitigation, and best practice, being to have the involved devices connected on a entirely private LAN. I've never tried connecting them to a "public" network.
Preach! I spent several hours this weekend trying to move my library between computers. So many popups and warnings telling me that I need to do something with no explanation of why. The docs are a mess. The library compatibility is a mess. Every few months they do something that fucks up libraries or makes them incompatible with some hardware. I just refuse updates now.
Rather than trying to make a new, shiny library, they should just release rekordbox 2.0, and then everyone would have a common lexicon to ask whether something is “rekordbox 2 compatible”. But instead we have this questionably compatible library plus as part of old, busted software that tries to brow best you into wrecking your old libraries.
I just use Claude to explain rekordbox to me now, and it is a bit more helpful than forums, though it also often gets confused from the conflicting advice/docs on the internet