PT-2025-26811 · Brother · Brother Devices

Published

2025-06-25

·

Updated

2026-03-30

·

CVE-2024-51978

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Brother printers (affected versions not specified) Fujifilm printers (affected versions not specified) Ricoh printers (affected versions not specified) Konica Minolta printers (affected versions not specified) Toshiba printers (affected versions not specified)
Description: An unauthenticated attacker who knows the target device's serial number can generate the default administrator password for the device. This allows attackers to bypass authentication and potentially gain remote access to the printer. The flaw affects hundreds of printer models from multiple vendors, including Brother, Fujifilm, Ricoh, Konica Minolta, and Toshiba. A critical flaw, identified as CVE-2024-51978, is rated 9.8 in severity and allows attackers to generate default admin passwords using device serial numbers. This vulnerability cannot be patched in some cases.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-51978

Affected Products

Brother Devices