CVE-2026-23767: Critical severity Seiko Epson ESC/POS vulnerability
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23767?
CVE-2026-23767 is rated as high severity due to lack of authentication, authorization, and encryption in ESC/POS commands.
How do I fix CVE-2026-23767?
To fix CVE-2026-23767, implement network segmentation and utilize secure communication methods to prevent unauthorized access.
What are the risks associated with CVE-2026-23767?
The risks associated with CVE-2026-23767 include unauthorized command execution and data interception due to unencrypted communications.
Which systems are affected by CVE-2026-23767?
CVE-2026-23767 affects systems utilizing Seiko Epson ESC/POS printer control language.
Is there a workaround for CVE-2026-23767?
A recommended workaround for CVE-2026-23767 is to limit network access to the devices using firewalls or IP filtering.