Rapid7 researchers uncovered eight significant vulnerabilities affecting hundreds of printer models from Brother and other vendors, which could lead to remote unauthorized access and device reconfiguration. Many of these flaws are exploitable without authentication, putting millions of enterprise and home printers at risk. #BrotherPrinters #PrinterVulnerabilities
Keypoints
- Rapid7 discovered eight vulnerabilities affecting multiple printer brands including Brother, Fujifilm, Ricoh, Konica Minolta, and Toshiba.
- The most critical flaw, CVE-2024-51978, allows attackers to bypass authentication using default administrator passwords generated from device serial numbers.
- Six of the eight vulnerabilities can be exploited without requiring authentication, enabling remote attacker access.
- Brother has patched most issues, but CVE-2024-51978 cannot be fully fixed through firmware updates in existing devices.
- Advisories have been issued by multiple vendors, including JPCERT/CC, indicating the widespread nature of these printer security flaws.
Read More: https://www.securityweek.com/new-vulnerabilities-expose-millions-of-brother-printers-to-hacking/