Epson records
34 published records for vendor epson.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 2.9%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-306 Missing Authentication for Critical Function3
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-798 Use of Hard-coded Credentials2
- CWE-427 Uncontrolled Search Path Element2
- CWE-276 Incorrect Default Permissions2
The weakness classes this vendor ships most often: where to look.
CWEAll records
34 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2017-12860No exploit | The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using aepson · easymp · CWE-798 | Critical9.8 | — | 3.5% | Oct 10, 2017 |
40Plan | CVE-2017-12861No exploit | The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using aepson · easymp · CWE-521 | Critical9.8 | — | 3.3% | Oct 10, 2017 |
39Monitor | CVE-2020-28929No exploit | Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely repson · eps tse server 8 firmware · CWE-306 | Critical9.8 | — | 1.2% | Dec 16, 2020 |
39Monitor | CVE-2026-23767No exploit | ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization,epson · sb-h50 firmware · CWE-306 | Critical9.8 | — | 0.5% | Mar 5, 2026 |
37Monitor | CVE-2020-6091No exploit | An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 Mepson · eb-1470ui firmware · CWE-288 | Critical9.1 | — | 2.4% | May 22, 2020 |
36Monitor | CVE-2018-19248No exploit | The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remoteepson · epson workforce wf-2861 firmware · CWE-306 | Critical9.1 | — | 1.5% | Dec 24, 2018 |
36Monitor | CVE-2022-36133No exploit | The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.epson · tm-c3500 firmware · CWE-287 | Critical9.1 | — | 0.7% | Nov 25, 2022 |
35Monitor | CVE-2018-5550No exploit | Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allowepson · airprint · CWE-79 | Medium6.1 | — | 36.9% | Feb 8, 2018 |
35Monitor | CVE-2020-12695Proof of concept | The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivenec · wr8165n · CWE-276 | High7.5 | — | 15.2% | Jun 8, 2020 |
35Monitor | CVE-2018-0689No exploit | HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780Nepson · ds-570w firmware · CWE-113 | High8.8 | — | 1.6% | Jan 9, 2019 |
35Monitor | CVE-2020-28931No exploit | Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to epson · eps tse server 8 firmware · CWE-352 | High8.8 | — | 0.5% | Dec 16, 2020 |
35Monitor | CVE-2019-20458No exploit | An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.CWE-276 | High8.8 | — | 0.4% | Nov 7, 2024 |
35Monitor | CVE-2019-20460No exploit | An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.CWE-352 | High8.8 | — | 0.2% | Nov 7, 2024 |
33Monitor | CVE-2019-20459No exploit | An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. | High8.4 | — | 0.3% | Nov 7, 2024 |
31Monitor | CVE-2020-5681No exploit | Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio Synerepson · epsonnet setupmanager · CWE-427 | High7.8 | — | 0.9% | Dec 23, 2020 |
31Monitor | CVE-2020-5674No exploit | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan hoepson · album print · CWE-427 | High7.8 | — | 0.3% | Nov 24, 2020 |
30Monitor | CVE-2018-19232No exploit | The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remoteepson · epson workforce wf-2861 firmware | High7.5 | — | 1.4% | Dec 24, 2018 |
30Monitor | CVE-2018-14902No exploit | The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access.epson · iprint · CWE-200 | High7.5 | — | 1.2% | Aug 30, 2018 |
30Monitor | CVE-2018-18959No exploit | An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices.epson · epson workforce wf-2861 firmware · CWE-119 | High7.5 | — | 1.2% | Dec 24, 2018 |
30Monitor | CVE-2018-14901No exploit | The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.epson · iprint · CWE-798 | High7.5 | — | 1.1% | Aug 30, 2018 |
30Monitor | CVE-2018-14900No exploit | On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.epson · wf-2750 firmware · CWE-417 | High7.5 | — | 1.1% | Aug 30, 2018 |
30Monitor | CVE-2023-38556No exploit | Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer.epson · ep-801a firmware | High7.5 | — | 0.9% | Aug 2, 2023 |
30Monitor | CVE-2018-14903No exploit | EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a epson · wf-2750 firmware · CWE-346 | High7.5 | — | 0.5% | Aug 30, 2018 |
27Monitor | CVE-2015-6034No exploit | EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to gain privileges via a epson · network utility · CWE-264 | Medium6.9 | — | 0.3% | Oct 28, 2015 |
26Monitor | CVE-2023-27520No exploit | Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attackeepson · lp-9200ps2 firmware · CWE-352 | Medium6.5 | — | 0.3% | Apr 11, 2023 |
- CVE-2017-1286040Plan
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a
CriticalCVSS 9.8No exploitEPSS 3%epson · easympOct 10, 2017
- CVE-2017-1286140Plan
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a
CriticalCVSS 9.8No exploitEPSS 3%epson · easympOct 10, 2017
- CVE-2020-2892939Monitor
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely r
CriticalCVSS 9.8No exploitEPSS 1%epson · eps tse server 8 firmwareDec 16, 2020
- CVE-2026-2376739Monitor
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization,
CriticalCVSS 9.8No exploitEPSS 0%epson · sb-h50 firmwareMar 5, 2026
- CVE-2020-609137Monitor
An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 M
CriticalCVSS 9.1No exploitEPSS 2%epson · eb-1470ui firmwareMay 22, 2020
- CVE-2018-1924836Monitor
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote
CriticalCVSS 9.1No exploitEPSS 1%epson · epson workforce wf-2861 firmwareDec 24, 2018
- CVE-2022-3613336Monitor
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.
CriticalCVSS 9.1No exploitEPSS 1%epson · tm-c3500 firmwareNov 25, 2022
- CVE-2018-555035Monitor
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow
MediumCVSS 6.1No exploitEPSS 37%epson · airprintFeb 8, 2018
- CVE-2020-1269535Monitor
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delive
HighCVSS 7.5Proof of conceptEPSS 15%nec · wr8165nJun 8, 2020
- CVE-2018-068935Monitor
HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N
HighCVSS 8.8No exploitEPSS 2%epson · ds-570w firmwareJan 9, 2019
- CVE-2020-2893135Monitor
Lack of an anti-CSRF token in the entire administrative interface in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to
HighCVSS 8.8No exploitEPSS 1%epson · eps tse server 8 firmwareDec 16, 2020
- CVE-2019-2045835Monitor
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.
HighCVSS 8.8No exploitEPSS 0%Nov 7, 2024
- CVE-2019-2046035Monitor
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.
HighCVSS 8.8No exploitEPSS 0%Nov 7, 2024
- CVE-2019-2045933Monitor
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices.
HighCVSS 8.4No exploitEPSS 0%Nov 7, 2024
- CVE-2020-568131Monitor
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio Syner
HighCVSS 7.8No exploitEPSS 1%epson · epsonnet setupmanagerDec 23, 2020
- CVE-2020-567431Monitor
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan ho
HighCVSS 7.8No exploitEPSS 0%epson · album printNov 24, 2020
- CVE-2018-1923230Monitor
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote
HighCVSS 7.5No exploitEPSS 1%epson · epson workforce wf-2861 firmwareDec 24, 2018
- CVE-2018-1490230Monitor
The ContentProvider in the EPSON iPrint application 6.6.3 for Android does not properly restrict data access.
HighCVSS 7.5No exploitEPSS 1%epson · iprintAug 30, 2018
- CVE-2018-1895930Monitor
An issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices.
HighCVSS 7.5No exploitEPSS 1%epson · epson workforce wf-2861 firmwareDec 24, 2018
- CVE-2018-1490130Monitor
The EPSON iPrint application 6.6.3 for Android contains hard-coded API and Secret keys for the Dropbox, Box, Evernote and OneDrive services.
HighCVSS 7.5No exploitEPSS 1%epson · iprintAug 30, 2018
- CVE-2018-1490030Monitor
On EPSON WF-2750 printers with firmware JP02I2, there is no filtering of print jobs.
HighCVSS 7.5No exploitEPSS 1%epson · wf-2750 firmwareAug 30, 2018
- CVE-2023-3855630Monitor
Improper input validation vulnerability in SEIKO EPSON printer Web Config allows a remote attacker to turned off the printer.
HighCVSS 7.5No exploitEPSS 1%epson · ep-801a firmwareAug 2, 2023
- CVE-2018-1490330Monitor
EPSON WF-2750 printers with firmware JP02I2 do not properly validate files before running updates, which allows remote attackers to cause a
HighCVSS 7.5No exploitEPSS 1%epson · wf-2750 firmwareAug 30, 2018
- CVE-2015-603427Monitor
EPSON Network Utility 4.10 uses weak permissions (Everyone: Full Control) for eEBSVC.exe, which allows local users to gain privileges via a
MediumCVSS 6.9No exploitEPSS 0%epson · network utilityOct 28, 2015
- CVE-2023-2752026Monitor
Cross-site request forgery (CSRF) vulnerability in SEIKO EPSON printers/network interface Web Config allows a remote unauthenticated attacke
MediumCVSS 6.5No exploitEPSS 0%epson · lp-9200ps2 firmwareApr 11, 2023