First published: Mon Dec 24 2018(Updated: )
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authentication by making a request to the /DOWN/FIRMWAREUPDATE/ROM1 URI and a POST request to the /FIRMWAREUPDATE URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Epson Workforce WF-2861 | =10.48_lq22i3 | |
Epson Workforce WF-2861 | =10.51.lq20i6 | |
Epson Workforce WF-2861 | =10.52.lq17ia | |
Epson Workforce WF-2861 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2018-19248.
CVE-2018-19248 has a severity rating of 9.1 (Critical).
CVE-2018-19248 allows remote attackers to upload a firmware file and reset the printer without authentication on Epson WorkForce WF-2861 devices.
No, authentication is not required for the exploitation of CVE-2018-19248.
To fix CVE-2018-19248, it is recommended to update the firmware of the affected Epson WorkForce WF-2861 devices to a version that addresses the vulnerability.