CVE-2018-19248: Critical severity Epson Epson Workforce Wf-2861 Firmware vulnerability
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authentication by making a request to the /DOWN/FIRMWAREUPDATE/ROM1 URI and a POST request to the /FIRMWAREUPDATE URI.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-19248.
What is the severity of CVE-2018-19248?
CVE-2018-19248 has a severity rating of 9.1 (Critical).
How does CVE-2018-19248 affect Epson WorkForce WF-2861 devices?
CVE-2018-19248 allows remote attackers to upload a firmware file and reset the printer without authentication on Epson WorkForce WF-2861 devices.
Is authentication required for the exploitation of CVE-2018-19248?
No, authentication is not required for the exploitation of CVE-2018-19248.
How can CVE-2018-19248 be fixed?
To fix CVE-2018-19248, it is recommended to update the firmware of the affected Epson WorkForce WF-2861 devices to a version that addresses the vulnerability.