Hundreds of Brother printer models have security flaw that can't be patched

A security company has found eight security vulnerabilities that impact hundreds of Brother printer models. The company has released firmware updates to handle seven of these vulnerabilities, but one security flaw cannot be patched. 

Brother has indicated that it'll fix the remaining issue during the manufacturing process of future printers, which doesn't help current owners. The company recommends that users change the default main password. Otherwise, bad actors could remotely access impacted devices. Though primarily impacting around 700 Brother printers, 59 units manufactured by Fujifilm, Toshiba, Ricoh and Konica Minolta are also at risk. 

🚨 Rapid7 discovered 8 new vulnerabilities while researching multifunction printers. 742 models across 4 vendors are affected by some or all of these vulns.

Rapid7 and @jpcert_en worked with #BrotherIndustries to coordinate the vulnerability disclosure: https://t.co/AOupYHaBqm pic.twitter.com/dig0LInkTg

— Rapid7 (@rapid7) June 25, 2025

The security flaw is called CVE-2024-51978 in the National Vulnerability Database, and has a 9.8 “Critical” CVSS rating. Simply put, attackers could generate the default admin password so long as they know the serial number of the printer.

Once this has been done, bad actors would be able to exploit the other seven vulnerabilities if the user didn't patch them up. These remaining flaws allow hackers to retrieve sensitive information, crash the device, open TCP connections, perform HTTP requests and reveal passwords for connected networks.

So what should you do? Check this list of impacted printers to see if you're at risk. Most importantly, change the default password. 

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/hundreds-of-brother-printer-models-have-security-flaw-that-cant-be-patched-165402227.html?src=rss https://www.engadget.com/cybersecurity/hundreds-of-brother-printer-models-have-security-flaw-that-cant-be-patched-165402227.html?src=rss
Utworzony 11h | 30 cze 2025, 17:30:16


Zaloguj się, aby dodać komentarz

Inne posty w tej grupie

Judge rules Apple must face antitrust lawsuit brought by the US DOJ

The US Department of Justice's antitrust

30 cze 2025, 22:10:23 | Engadget
How to buy the Switch 2: Nintendo's restock updates from Walmart, Best Buy and more

The Nintendo Switch 2 has been available in the US for more than three weeks — and we finally saw a second wave of a

30 cze 2025, 22:10:22 | Engadget
Apple may power Siri with Anthropic or OpenAI models amid AI struggles

Apple is considering using AI models from OpenAI or Anthropic to deliver the

30 cze 2025, 22:10:21 | Engadget
Video Games Weekly: Summer Game Fest ends when I say so

Welcome to Video Games Weekly on Engadget. Expect a new story every Monday or Tuesday, broken into two parts. The first is a space for short essays and ramblings about video game trends and rel

30 cze 2025, 22:10:20 | Engadget