PT-2024-10734 · Epson · Epson Expression Home Xp255
Konrad Leszczynski
·
Published
2024-11-07
·
Updated
2024-11-11
·
CVE-2019-20458
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Epson Expression Home XP255 version 20.08.FM10I8
Description
An issue was discovered where the device comes without a password and the user is not prompted to set one up, allowing anyone to access the web admin panel and become admin without credentials.
Recommendations
For Epson Expression Home XP255 version 20.08.FM10I8, consider setting up a password for the device to prevent unauthorized access to the web admin panel. As a temporary workaround, restrict access to the web admin panel until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Epson Expression Home Xp255