Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · epson

epson

· 4 Critical

Total CVEs

31

Critical

4

Products

516

Search All CVEs →

31

Products (516)

epson workforce wf-28614 CVEsepson workforce wf-2861 firmware4 CVEslp-s71003 CVEseps tse server 8 firmware3 CVEseps tse server 83 CVEswf-27503 CVEswf-2750 firmware3 CVEslp-s90003 CVEslp-s40002 CVEsds-570w2 CVEsds-570w firmware2 CVEsds-780n2 CVEsds-780n firmware2 CVEseasymp2 CVEsep-10va2 CVEsep-10va firmware2 CVEsep-30va2 CVEsep-30va firmware2 CVEsep-707a2 CVEsep-707a firmware2 CVEsep-708a2 CVEsep-708a firmware2 CVEsep-709a2 CVEsep-709a firmware2 CVEsep-777a2 CVEsep-777a firmware2 CVEsep-807ab2 CVEsep-807ab firmware2 CVEsep-807ar2 CVEsep-807ar firmware2 CVEsep-807aw2 CVEsep-807aw firmware2 CVEsep-808ab2 CVEsep-808ab firmware2 CVEsep-808ar2 CVEsep-808ar firmware2 CVEsep-808aw2 CVEsep-808aw firmware2 CVEsep-879ab2 CVEsep-879ab firmware2 CVEsep-879ar2 CVEsep-879ar firmware2 CVEsep-879aw2 CVEsep-879aw firmware2 CVEsep-907f2 CVEsep-907f firmware2 CVEsep-977a32 CVEsep-977a3 firmware2 CVEsep-978a32 CVEsep-978a3 firmware2 CVEsep-979a32 CVEsep-979a3 firmware2 CVEsep-m570t2 CVEsep-m570t firmware2 CVEsesifnw12 CVEsesifnw1 firmware2 CVEsesnsb12 CVEsesnsb1 firmware2 CVEsesnsb22 CVEsesnsb2 firmware2 CVEsew-m5071ft2 CVEsew-m5071ft firmware2 CVEsew-m660ft2 CVEsew-m660ft firmware2 CVEsew-m770t2 CVEsew-m770t firmware2 CVEsiprint2 CVEsiprojection2 CVEslp-8200c2 CVEslp-8200c firmware2 CVEslp-8500c2 CVEslp-8500c firmware2 CVEslp-8700ps32 CVEslp-8700ps3 firmware2 CVEslp-9200b2 CVEslp-9200b firmware2 CVEslp-9200c2 CVEslp-9200c firmware2 CVEslp-9200ps22 CVEslp-9200ps2 firmware2 CVEslp-9200ps32 CVEslp-9200ps3 firmware2 CVEslp-93002 CVEslp-9300 firmware2 CVEslp-96002 CVEslp-9600 firmware2 CVEslp-9600s2 CVEslp-9600s firmware2 CVEslp-9800c2 CVEslp-9800c firmware2 CVEslp-s30002 CVEslp-s3000 firmware2 CVEslp-s3000ps2 CVEslp-s3000ps firmware2 CVEslp-s3000r2 CVEslp-s3000r firmware2 CVEslp-s3000z2 CVEslp-s3000z firmware2 CVEslp-s300n2 CVEslp-s300n firmware2 CVEslp-s310n2 CVEslp-s310n firmware2 CVEslp-s35002 CVEslp-s3500 firmware2 CVEslp-s4000 firmware2 CVEslp-s42002 CVEslp-s4200 firmware2 CVEslp-s45002 CVEslp-s4500 firmware2 CVEslp-s50002 CVEslp-s5000 firmware2 CVEslp-s53002 CVEslp-s5300 firmware2 CVEslp-s5300r2 CVEslp-s5300r firmware2 CVEslp-s55002 CVEslp-s5500 firmware2 CVEslp-s60002 CVEslp-s6000 firmware2 CVEslp-s65002 CVEslp-s6500 firmware2 CVEslp-s70002 CVEslp-s7000 firmware2 CVEslp-s7100 firmware2 CVEslp-s75002 CVEslp-s7500 firmware2 CVEslp-s7500ps2 CVEslp-s7500ps firmware2 CVEslp-s81002 CVEslp-s8100 firmware2 CVEslp-s9000 firmware2 CVEspa-w11g2 CVEspa-w11g22 CVEspa-w11g2 firmware2 CVEspa-w11g firmware2 CVEspf-702 CVEspf-70 firmware2 CVEspf-712 CVEspf-71 firmware2 CVEspf-812 CVEspf-81 firmware2 CVEsprifnw12 CVEsprifnw1 firmware2 CVEsprifnw1s2 CVEsprifnw1s firmware2 CVEsprifnw22 CVEsprifnw2 firmware2 CVEsprifnw2ac2 CVEsprifnw2ac firmware2 CVEsprifnw2s2 CVEsprifnw2s firmware2 CVEsprifnw2sac2 CVEsprifnw2sac firmware2 CVEsprifnw32 CVEsprifnw3 firmware2 CVEsprifnw3s2 CVEsprifnw3s firmware2 CVEsprifnw62 CVEsprifnw6 firmware2 CVEsprifnw72 CVEsprifnw7 firmware2 CVEsprifnw7s2 CVEsprifnw7s firmware2 CVEsprifnw7u2 CVEsprifnw7u firmware2 CVEspx-048a2 CVEspx-048a firmware2 CVEspx-049a2 CVEspx-049a firmware2 CVEspx-437a2 CVEspx-437a firmware2 CVEspx-m350f2 CVEspx-m350f firmware2 CVEspx-m5040f2 CVEspx-m5040f firmware2 CVEspx-m5041f2 CVEspx-m5041f firmware2 CVEspx-m650a2 CVEspx-m650a firmware2 CVEspx-m650f2 CVEspx-m650f firmware2 CVEspx-m680f2 CVEspx-m680f firmware2 CVEspx-m7050f2 CVEspx-m7050f firmware2 CVEspx-m7050fp2 CVEspx-m7050fp firmware2 CVEspx-m7050fx2 CVEspx-m7050fx firmware2 CVEspx-m7070fx2 CVEspx-m7070fx firmware2 CVEspx-m740f2 CVEspx-m740f firmware2 CVEspx-m781f2 CVEspx-m781f firmware2 CVEspx-m840f2 CVEspx-m840f firmware2 CVEspx-m840fx2 CVEspx-m840fx firmware2 CVEspx-m860f2 CVEspx-m860f firmware2 CVEspx-s05b2 CVEspx-s05b firmware2 CVEspx-s05w2 CVEspx-s05w firmware2 CVEspx-s3502 CVEspx-s350 firmware2 CVEspx-s50402 CVEspx-s5040 firmware2 CVEspx-s70502 CVEspx-s7050 firmware2 CVEspx-s7050ps2 CVEspx-s7050ps firmware2 CVEspx-s7050x2 CVEspx-s7050x firmware2 CVEspx-s7070x2 CVEspx-s7070x firmware2 CVEspx-s7402 CVEspx-s740 firmware2 CVEspx-s8402 CVEspx-s840 firmware2 CVEspx-s840x2 CVEspx-s840x firmware2 CVEspx-s8602 CVEspx-s860 firmware2 CVEstm-c35002 CVEstm-c3500 firmware2 CVEstm-c75002 CVEstm-c7500 firmware2 CVEspx-5002 firmware1 CVEspx-502a1 CVEspx-502a firmware1 CVEspx-58001 CVEspx-5800 firmware1 CVEspx-5v1 CVEspx-5v firmware1 CVEspx-601f1 CVEspx-601f firmware1 CVEspx-602f1 CVEspx-602f firmware1 CVEspx-6250s1 CVEspx-6250s firmware1 CVEspx-65501 CVEspx-6550 firmware1 CVEspx-7500n1 CVEspx-7500n firmware1 CVEspx-75501 CVEspx-7550 firmware1 CVEspx-7550s1 CVEspx-7550s firmware1 CVEspx-7v1 CVEspx-7v firmware1 CVEspx-9500n1 CVEspx-9500n firmware1 CVEspx-95501 CVEspx-9550 firmware1 CVEspx-9550s1 CVEspx-9550s firmware1 CVEspx-b5001 CVEspx-b500 firmware1 CVEspx-b5101 CVEspx-b510 firmware1 CVEspx-f100001 CVEspx-f10000 firmware1 CVEspx-f80001 CVEspx-f8000 firmware1 CVEspx-f8000m1 CVEspx-f8000m firmware1 CVEspx-h100001 CVEspx-h10000 firmware1 CVEspx-h60001 CVEspx-h6000 firmware1 CVEspx-h70001 CVEspx-h7000 firmware1 CVEspx-h80001 CVEspx-h8000 firmware1 CVEspx-h90001 CVEspx-h9000 firmware1 CVEstm-m30ii-s1 CVEstm-m30ii-s firmware1 CVEstm-m30ii-sl1 CVEstm-m30ii-sl firmware1 CVEstm-m30ii firmware1 CVEstm-m30iii1 CVEstm-m30iii-h1 CVEstm-m30iii-h firmware1 CVEstm-m30iii firmware1 CVEstm-m551 CVEstm-m55 firmware1 CVEstm-p201 CVEstm-p20 firmware1 CVEstm-p20ii1 CVEstm-p20ii firmware1 CVEstm-p60ii1 CVEstm-p60ii firmware1 CVEstm-p801 CVEstm-p80 firmware1 CVEstm-p80ii1 CVEstm-p80ii firmware1 CVEstm-t20ii1 CVEseasy settings1 CVEstm-t20ii firmware1 CVEseb-1470ui1 CVEseb-1470ui firmware1 CVEsec-011 CVEsec-01 firmware1 CVEsep-1011 CVEstm-t20iii1 CVEstm-t20iii firmware1 CVEstm-t88vi1 CVEstm-t88vi-ihub1 CVEstm-t88vi-ihub firmware1 CVEstm-t88vi firmware1 CVEstm-t88vii1 CVEstm-t88vii firmware1 CVEstmnet webconfig1 CVEsub-e041 CVEsub-e04 firmware1 CVEsub-r041 CVEsep-801a1 CVEsep-801a firmware1 CVEsep-802a1 CVEsep-802a firmware1 CVEsub-r04 firmware1 CVEsuniversal print driver1 CVEsweb to page1 CVEswebconfig1 CVEscolor calibration utility1 CVEsalbum print1 CVEsxp-1001 CVEsxp-21011 CVEsxp-21051 CVEsxp-2411 CVEsxp-3201 CVEsxp-3301 CVEsxp-3401 CVEsxp-41001 CVEsxp-41051 CVEsxp-4401 CVEsxp-6201 CVEsxp-6301 CVEsep-901a1 CVEsep-901a firmware1 CVEsep-901f1 CVEsep-901f firmware1 CVEsep-902a1 CVEsep-902a firmware1 CVEsxp-7021 CVEspx-w80001 CVEspx-w8000 firmware1 CVEsremote printer driver1 CVEssb-h501 CVEssb-h50 firmware1 CVEssc-f20001 CVEssc-f2000 firmware1 CVEssc-f21501 CVEssc-f2150 firmware1 CVEseasy photo print1 CVEse-photo1 CVEscreativity suite1 CVEsconnect1 CVEsepsonnet setupmanager1 CVEssc-f60001 CVEssc-f6000 firmware1 CVEssc-f62001 CVEssc-f6200 firmware1 CVEssc-f63501 CVEssc-f6350 firmware1 CVEssc-f71001 CVEssc-f7100 firmware1 CVEssc-f72001 CVEssc-f7200 firmware1 CVEssc-f92001 CVEssc-f9200 firmware1 CVEsew-m970a3t1 CVEsimaging workshop1 CVEssc-f93501 CVEssc-f9350 firmware1 CVEslink21 CVEssc-f94501 CVEssc-f9450 firmware1 CVEssc-f9450h1 CVEssc-f9450h firmware1 CVEssc-p100501 CVEssc-p10050 firmware1 CVEssc-p200501 CVEssc-p20050 firmware1 CVEssc-p50501 CVEssc-p5050 firmware1 CVEssc-p60501 CVEssc-p6050 firmware1 CVEssc-p70501 CVEssc-p7050 firmware1 CVEssc-p80501 CVEssc-p8050 firmware1 CVEssc-p90501 CVEssc-p9050 firmware1 CVEssc-px3v1 CVEssc-px3v firmware1 CVEssc-px5v21 CVEssc-px5v2 firmware1 CVEssc-px7v21 CVEssc-px7v2 firmware1 CVEssc-s306501 CVEssc-s30650 firmware1 CVEssc-s406501 CVEssc-s40650 firmware1 CVEssc-s506501 CVEssc-s50650 firmware1 CVEssc-s606501 CVEssc-s60650 firmware1 CVEssc-s60650l1 CVEssc-s60650l firmware1 CVEssc-s706501 CVEssc-s70650 firmware1 CVEsairprint1 CVEssc-s806501 CVEssc-s80650 firmware1 CVEssc-s80650l1 CVEssc-s80650l firmware1 CVEssc-t30501 CVEssc-t3050 firmware1 CVEssc-t32501 CVEssc-t3250 firmware1 CVEssc-t32551 CVEssc-t3255 firmware1 CVEssc-t50501 CVEssc-t5050 firmware1 CVEssc-t52501 CVEssc-t5250 firmware1 CVEssc-t5250d1 CVEssc-t5250d firmware1 CVEssc-t52551 CVEssc-t5255 firmware1 CVEssc-t5255d1 CVEscolorio easy print1 CVEslp-s7100 driver 4.1.01 CVEslp-s7100 driver 4.1.71 CVEssc-t5255d firmware1 CVEssc-t70501 CVEssc-t7050 firmware1 CVEssc-t72501 CVEssc-t7250 firmware1 CVEssc-t7250d1 CVEssc-t7250d firmware1 CVEscolorbase1 CVEslp-s9000 driver 4.1.01 CVEslp-s9000 driver 4.1.111 CVEssc-t72551 CVEsm571t1 CVEsmulti-print quicker1 CVEsnet config1 CVEsnet config se1 CVEsnet print1 CVEsnet software development kit1 CVEsnetwork utility1 CVEsoffirio synergyware printdirector1 CVEspa-tcu11 CVEspa-tcu1 firmware1 CVEssc-t7255 firmware1 CVEssc-t7255d1 CVEssc-t7255d firmware1 CVEsscan icm updater1 CVEsscanner driver1 CVEsstatus monitor 21 CVEsstatus monitor 31 CVEsstylus pro gs60001 CVEsstylus pro gs6000 firmware1 CVEstm-c34001 CVEsphotolier1 CVEsphotoquicker1 CVEsphotostarter1 CVEspm-t9601 CVEspm-t960 firmware1 CVEspm-t9901 CVEspm-t990 firmware1 CVEspm-t990 integrated installer1 CVEstm-c3400 firmware1 CVEsxp-85001 CVEsxp-86001 CVEstm-c35101 CVEstm-c3510 firmware1 CVEstm-c35201 CVEstm-c3520 firmware1 CVEsxp-9601 CVEsxp-9701 CVEstm-c7500g1 CVEstm-c7500g firmware1 CVEstm-c75101 CVEstm-c7510 firmware1 CVEstm-c7510g1 CVEstm-c7510g firmware1 CVEstm-c75201 CVEstm-c7520 firmware1 CVEstm-c7520g1 CVEstm-c7520g firmware1 CVEstm-h6000v1 CVEstm-h6000v firmware1 CVEstm-l1001 CVEstm-l100 firmware1 CVEstm-m101 CVEsprint1 CVEsprint image framer tool1 CVEsprint layout1 CVEsprolab print1 CVEstm-m10 firmware1 CVEstm-m301 CVEstm-m30 firmware1 CVEstm-m30ii1 CVEspx-200001 CVEspx-20000 firmware1 CVEspx-2011 CVEspx-201 firmware1 CVEstm-m30ii-h1 CVEstm-m30ii-h firmware1 CVEspx-50021 CVEs

Recent Vulnerabilities

View all 31
CVE-2026-23767CRITICAL 9.8

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.

CVE-2023-38556HIGH 7.5

Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers via a web browser. Web Config is pre-installed in some printers provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

CVE-2023-27520MEDIUM 6.5

Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacker to hijack the authentication and perform unintended operations by having a logged-in user view a malicious page. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

CVE-2023-23572MEDIUM 4.8

Cross-site scripting vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote authenticated attacker with an administrative privilege to inject an arbitrary script. [Note] Web Config is the software that allows users to check the status and change the settings of SEIKO EPSON printers/network interface via a web browser. According to SEIKO EPSON CORPORATION, it is also called as Remote Manager in some products. Web Config is pre-installed in some printers/network interface provided by SEIKO EPSON CORPORATION. For the details of the affected product names/model numbers, refer to the information provided by the vendor.

CVE-2022-36133CRITICAL 9.1

The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.

CVE-2020-9453MEDIUM 5.5

In Epson iProjection v2.30, the driver file EMP_MPAU.sys allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C402406 and IOCtl 0x9C40240A. (0x9C402402 has only a NULL pointer dereference.) This affects \Device\EMPMPAUIO and \DosDevices\EMPMPAU.

CVE-2020-9014MEDIUM 5.5

In Epson iProjection v2.30, the driver file (EMP_NSAU.sys) allows local users to cause a denial of service (BSOD) via crafted input to the virtual audio device driver with IOCTL 0x9C402402, 0x9C402406, or 0x9C40240A. \Device\EMPNSAUIO and \DosDevices\EMPNSAU are similarly affected.

CVE-2020-5681HIGH 7.8

Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVE-2020-28931HIGH 8.8

Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to force an administrator to execute external POST requests by visiting a malicious website.

CVE-2020-28930MEDIUM 5.4

A Cross-Site Scripting (XSS) issue in the 'update user' and 'delete user' functionalities in settings/users.php in EPSON EPS TSE Server 8 (21.0.11) allows an authenticated attacker to inject a JavaScript payload in the user management page that is executed by an administrator.

CVE-2020-28929CRITICAL 9.8

Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credentials via the maintenance/troubleshoot.php?download=1 URI.

CVE-2020-5674HIGH 7.8

Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

CVE-2020-12695HIGH 7.5

The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

CVE-2020-6091CRITICAL 9.1

An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MAIN2: 8X7325WWV303. A specially crafted series of HTTP requests can cause authentication bypass resulting in information disclosure. An attacker can send an HTTP request to trigger this vulnerability.

CVE-2018-0689

HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A firmware versions released prior to 2017 August 1, EP-708A firmware versions released prior to 2017 August 7, EP-709A firmware versions released prior to 2017 June 12, EP-777A firmware versions released prior to 2017 August 1, EP-807AB/AW/AR firmware versions released prior to 2017 August 1, EP-808AB/AW/AR firmware versions released prior to 2017 August 7, EP-879AB/AW/AR firmware versions released prior to 2017 June 12, EP-907F firmware versions released prior to 2017 August 1, EP-977A3 firmware versions released prior to 2017 August 1, EP-978A3 firmware versions released prior to 2017 August 7, EP-979A3 firmware versions released prior to 2017 June 12, EP-M570T firmware versions released prior to 2017 September 6, EW-M5071FT firmware versions released prior to 2017 November 2, EW-M660FT firmware versions released prior to 2018 April 19, EW-M770T firmware versions released prior to 2017 September 6, PF-70 firmware versions released prior to 2018 April 20, PF-71 firmware versions released prior to 2017 July 18, PF-81 firmware versions released prior to 2017 September 14, PX-048A firmware versions released prior to 2017 July 4, PX-049A firmware versions released prior to 2017 September 11, PX-437A firmware versions released prior to 2017 July 24, PX-M350F firmware versions released prior to 2018 February 23, PX-M5040F firmware versions released prior to 2017 November 20, PX-M5041F firmware versions released prior to 2017 November 20, PX-M650A firmware versions released prior to 2017 October 17, PX-M650F firmware versions released prior to 2017 October 17, PX-M680F firmware versions released prior to 2017 June 29, PX-M7050F firmware versions released prior to 2017 October 13, PX-M7050FP firmware versions released prior to 2017 October 13, PX-M7050FX firmware versions released prior to 2017 November 7, PX-M7070FX firmware versions released prior to 2017 April 27, PX-M740F firmware versions released prior to 2017 December 4, PX-M741F firmware versions released prior to 2017 December 4, PX-M780F firmware versions released prior to 2017 June 29, PX-M781F firmware versions released prior to 2017 June 27, PX-M840F firmware versions released prior to 2017 November 16, PX-M840FX firmware versions released prior to 2017 December 8, PX-M860F firmware versions released prior to 2017 October 25, PX-S05B/W firmware versions released prior to 2018 March 9, PX-S350 firmware versions released prior to 2018 February 23, PX-S5040 firmware versions released prior to 2017 November 20, PX-S7050 firmware versions released prior to 2018 February 21, PX-S7050PS firmware versions released prior to 2018 February 21, PX-S7050X firmware versions released prior to 2017 November 7, PX-S7070X firmware versions released prior to 2017 April 27, PX-S740 firmware versions released prior to 2017 December 3, PX-S840 firmware versions released prior to 2017 November 16, PX-S840X firmware versions released prior to 2017 December 8, PX-S860 firmware versions released prior to 2017 December 7) may allow a remote attackers to lead a user to a phishing site or execute an arbitrary script on the user's web browser.

CVE-2018-0688

Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A firmware versions released prior to 2017 August 1, EP-708A firmware versions released prior to 2017 August 7, EP-709A firmware versions released prior to 2017 June 12, EP-777A firmware versions released prior to 2017 August 1, EP-807AB/AW/AR firmware versions released prior to 2017 August 1, EP-808AB/AW/AR firmware versions released prior to 2017 August 7, EP-879AB/AW/AR firmware versions released prior to 2017 June 12, EP-907F firmware versions released prior to 2017 August 1, EP-977A3 firmware versions released prior to 2017 August 1, EP-978A3 firmware versions released prior to 2017 August 7, EP-979A3 firmware versions released prior to 2017 June 12, EP-M570T firmware versions released prior to 2017 September 6, EW-M5071FT firmware versions released prior to 2017 November 2, EW-M660FT firmware versions released prior to 2018 April 19, EW-M770T firmware versions released prior to 2017 September 6, PF-70 firmware versions released prior to 2018 April 20, PF-71 firmware versions released prior to 2017 July 18, PF-81 firmware versions released prior to 2017 September 14, PX-048A firmware versions released prior to 2017 July 4, PX-049A firmware versions released prior to 2017 September 11, PX-437A firmware versions released prior to 2017 July 24, PX-M350F firmware versions released prior to 2018 February 23, PX-M5040F firmware versions released prior to 2017 November 20, PX-M5041F firmware versions released prior to 2017 November 20, PX-M650A firmware versions released prior to 2017 October 17, PX-M650F firmware versions released prior to 2017 October 17, PX-M680F firmware versions released prior to 2017 June 29, PX-M7050F firmware versions released prior to 2017 October 13, PX-M7050FP firmware versions released prior to 2017 October 13, PX-M7050FX firmware versions released prior to 2017 November 7, PX-M7070FX firmware versions released prior to 2017 April 27, PX-M740F firmware versions released prior to 2017 December 4, PX-M741F firmware versions released prior to 2017 December 4, PX-M780F firmware versions released prior to 2017 June 29, PX-M781F firmware versions released prior to 2017 June 27, PX-M840F firmware versions released prior to 2017 November 16, PX-M840FX firmware versions released prior to 2017 December 8, PX-M860F firmware versions released prior to 2017 October 25, PX-S05B/W firmware versions released prior to 2018 March 9, PX-S350 firmware versions released prior to 2018 February 23, PX-S5040 firmware versions released prior to 2017 November 20, PX-S7050 firmware versions released prior to 2018 February 21, PX-S7050PS firmware versions released prior to 2018 February 21, PX-S7050X firmware versions released prior to 2017 November 7, PX-S7070X firmware versions released prior to 2017 April 27, PX-S740 firmware versions released prior to 2017 December 3, PX-S840 firmware versions released prior to 2017 November 16, PX-S840X firmware versions released prior to 2017 December 8, PX-S860 firmware versions released prior to 2017 December 7) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the web interface of the affected product.

CVE-2018-19248

The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and reset the printer without authentication by making a request to the /DOWN/FIRMWAREUPDATE/ROM1 URI and a POST request to the /FIRMWAREUPDATE URI.

CVE-2018-19232

The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to cause a denial of service via a FIRMWAREUPDATE GET request, as demonstrated by the /DOWN/FIRMWAREUPDATE/ROM1 URI.

CVE-2018-18960

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. They use SNMP to find certain devices on the network, but the default version is v2c, allowing an amplification attack.

CVE-2018-18959

An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web page, if the data for 'Bonjour Service Location' at /PRESENTATION/BONJOUR is more than 251 bytes when sending data for Air Print Setting, then the device no longer functions until a reboot.

CVE-2018-14903

EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a printer malfunction or send malicious data to the printer.

CVE-2018-14902

The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access. This allows an attacker's application to read scanned documents.

CVE-2018-14901

The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.

CVE-2018-14900

On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs. Remote attackers can send print jobs directly to the printer via TCP port 9100.

CVE-2018-14899

On the EPSON WF-2750 printer with firmware JP02I2, the Web interface AirPrint Setup page is vulnerable to HTML Injection that can redirect users to malicious sites.