Hundreds of Brother printer models have security flaw that can't be patched

A security company has found eight security vulnerabilities that impact hundreds of Brother printer models. The company has released firmware updates to handle seven of these vulnerabilities, but one security flaw cannot be patched. 

Brother has indicated that it'll fix the remaining issue during the manufacturing process of future printers, which doesn't help current owners. The company recommends that users change the default main password. Otherwise, bad actors could remotely access impacted devices. Though primarily impacting around 700 Brother printers, 59 units manufactured by Fujifilm, Toshiba, Ricoh and Konica Minolta are also at risk. 

🚨 Rapid7 discovered 8 new vulnerabilities while researching multifunction printers. 742 models across 4 vendors are affected by some or all of these vulns.

Rapid7 and @jpcert_en worked with #BrotherIndustries to coordinate the vulnerability disclosure: https://t.co/AOupYHaBqm pic.twitter.com/dig0LInkTg

— Rapid7 (@rapid7) June 25, 2025

The security flaw is called CVE-2024-51978 in the National Vulnerability Database, and has a 9.8 “Critical” CVSS rating. Simply put, attackers could generate the default admin password so long as they know the serial number of the printer.

Once this has been done, bad actors would be able to exploit the other seven vulnerabilities if the user didn't patch them up. These remaining flaws allow hackers to retrieve sensitive information, crash the device, open TCP connections, perform HTTP requests and reveal passwords for connected networks.

So what should you do? Check this list of impacted printers to see if you're at risk. Most importantly, change the default password. 

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/hundreds-of-brother-printer-models-have-security-flaw-that-cant-be-patched-165402227.html?src=rss https://www.engadget.com/cybersecurity/hundreds-of-brother-printer-models-have-security-flaw-that-cant-be-patched-165402227.html?src=rss
Vytvorené 2d | 30. 6. 2025, 17:30:16


Ak chcete pridať komentár, prihláste sa

Ostatné príspevky v tejto skupine

Even before the Xbox layoffs, there was 'tension' at Halo Studios

At least five employees at Halo Studios have been fired as part of

3. 7. 2025, 1:20:08 | Engadget
Blizzard is giving up on its Warcraft mobile game amid layoffs

It's nearly the end of the road for Warcraft Rumble.

2. 7. 2025, 22:50:14 | Engadget
The Last of Us co-creator Neil Druckmann is stepping away from the show to focus on future games

Neil Druckmann, head of the PlayStation studio Naughty Dog and co-creator of The Last of Us, is stepping away from the HBO show based on the 2013 game and its 2020 sequel to focus his work

2. 7. 2025, 20:30:20 | Engadget
How to watch Summer Games Done Quick 2025

In a mad, mad world, speedruns for charity can be a calm oasis. Summer Games Done Quick (SGDQ) has your fix with the 2025 edition of the marathon. You can tune in starting on Sunday, July 6. As usu

2. 7. 2025, 20:30:18 | Engadget
Former Ubisoft executives convicted in France

French video game giant Ubisoft has been embroiled in a multiyear saga regarding a

2. 7. 2025, 20:30:16 | Engadget