CVE-2019-20458: High severity epson expression home xp255 vulnerability
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-20458?
CVE-2019-20458 has a medium severity rating due to the lack of default password protection on the device.
How do I fix CVE-2019-20458?
To fix CVE-2019-20458, manually set a password on the Epson Expression Home XP255 device to enhance security.
Who is affected by CVE-2019-20458?
Users of the Epson Expression Home XP255 devices running the default firmware are affected by CVE-2019-20458.
What are the risks associated with CVE-2019-20458?
The risks associated with CVE-2019-20458 include unauthorized access to the device and potential data exposure.
Is there a patch available for CVE-2019-20458?
There is currently no official patch available for CVE-2019-20458; users must secure the device manually.