Hundreds of Brother printer models have security flaw that can't be patched

A security company has found eight security vulnerabilities that impact hundreds of Brother printer models. The company has released firmware updates to handle seven of these vulnerabilities, but one security flaw cannot be patched. 

Brother has indicated that it'll fix the remaining issue during the manufacturing process of future printers, which doesn't help current owners. The company recommends that users change the default main password. Otherwise, bad actors could remotely access impacted devices. Though primarily impacting around 700 Brother printers, 59 units manufactured by Fujifilm, Toshiba, Ricoh and Konica Minolta are also at risk. 

🚨 Rapid7 discovered 8 new vulnerabilities while researching multifunction printers. 742 models across 4 vendors are affected by some or all of these vulns.

Rapid7 and @jpcert_en worked with #BrotherIndustries to coordinate the vulnerability disclosure: https://t.co/AOupYHaBqm pic.twitter.com/dig0LInkTg

— Rapid7 (@rapid7) June 25, 2025

The security flaw is called CVE-2024-51978 in the National Vulnerability Database, and has a 9.8 “Critical” CVSS rating. Simply put, attackers could generate the default admin password so long as they know the serial number of the printer.

Once this has been done, bad actors would be able to exploit the other seven vulnerabilities if the user didn't patch them up. These remaining flaws allow hackers to retrieve sensitive information, crash the device, open TCP connections, perform HTTP requests and reveal passwords for connected networks.

So what should you do? Check this list of impacted printers to see if you're at risk. Most importantly, change the default password. 

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/hundreds-of-brother-printer-models-have-security-flaw-that-cant-be-patched-165402227.html?src=rss https://www.engadget.com/cybersecurity/hundreds-of-brother-printer-models-have-security-flaw-that-cant-be-patched-165402227.html?src=rss
созданный 1d | 30 июн. 2025 г., 17:30:16


Войдите, чтобы добавить комментарий

Другие сообщения в этой группе

Marshall’s new Middleton II Bluetooth speaker lasts 30 hours between charges

Marshall has launched its latest compact Bluetooth speaker, the Middleton II. A direct replacement for the first-generation

1 июл. 2025 г., 19:10:24 | Engadget
The FCC delays enforcement of prison call rate caps

Chalk one up for prison telecoms — and against inmates' family members — courtesy of Trump's FCC. On Monday, the agency

1 июл. 2025 г., 19:10:23 | Engadget
Amazon unveils its Prime Gaming freebies for July 2025

Amazon announced a fresh batch of games that it's giving away for free or nearly free in July. The company's cloud gaming platform, Amazon Luna, has a few notable standouts on its lineup of free ti

1 июл. 2025 г., 19:10:22 | Engadget
The $799 Nothing Phone 3 has four 50MP cameras and a secondary micro-LED display

The wait is over. Nothing has officially announced the Phone 3, its first flagship smartphone since entering the market in

1 июл. 2025 г., 19:10:21 | Engadget
Nothing’s first over-ear headphones want to be a quirky $300 AirPods Max alternative

After numerous waves of similar (and not-so-similar)

1 июл. 2025 г., 19:10:19 | Engadget
Nothing Phone 3 hands-on: A tiny, playful dot-matrix screen in the company's most expensive phone yet

With the third generation of its smartphone series, Nothing made the unusual move to launch the cheaper ‘a’ line first, unveiling

1 июл. 2025 г., 19:10:18 | Engadget
Xbox's first Game Pass additions for July include Tony Hawk’s Pro Skater 3 + 4

Xbox has confirmed the first batch of Game Pass additions for July. The headliner this

1 июл. 2025 г., 16:40:40 | Engadget