PT-2025-26810 · Unknown · Network Printer
Published
2025-06-25
·
Updated
2025-08-15
·
CVE-2024-51977
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Brother, FUJIFILM, RICOH, Toshiba Tec, and Konica Minolta Printers (affected versions not specified)
Description:
An unauthenticated attacker with access to the HTTP service (TCP port 80), HTTPS service (TCP port 443), or IPP service (TCP port 631) can leak sensitive information from a vulnerable device. Accessing the URI path
/etc/mnt info.csv via a GET request does not require authentication and returns a comma separated value (CSV) table containing the device’s model, firmware version, IP address, and serial number. The CrowdSec Network has detected exploitation attempts targeting this issue, affecting over 750 different printer models. The leaked information can be used to generate a valid administrator account.Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Network Printer