Command Execution Vulnerability in Epson WebConfig

Vulnerability Reference: CVE-2025-*****

 
Description:
An administrator password is required to log in to WebConfig.
A malicious third party who obtains the administrator password can execute arbitrary commands by logging in to Web Config and entering a specific string on a specific screen.
  
Impact:
The product settings could be reset, or ping packets could be sent to other devices.
There are no reports of attacks exploiting this vulnerability until now.
  
Solution:
We strongly recommend taking workaround to mitigate the impact of this vulnerability.
To ensure the security of your Epson product, we recommend end-users and their administrators to implement and maintain industry-standard security controls and practices in setting up and managing password and network to which the product is connected.
  
Administrator Password
      
  • Please set a unique password for each product.
  •   
  • The administrator password should be a complex string of characters that is difficult for others to guess, such as eight or more characters that contain not only English letters but also symbols and numbers.
  
Internet Connection
      
  • Do not connect the product directly to the Internet; install it within a network protected by a firewall.
  •   
  • Please set a private IP address for the product.
For more information on securing your Epson product, please refer our Epson Security Guidebook. The Epson Security Guidebook is available on the following website:
Epson Security Guidebook

 

Affected Products
▶ Laser Printers
  • AL-C300DN
  • AL-M300DN
  • AL-M310DN
  • AL-M320DN
  • AL-M400DN
  • AL-M8100DN
▶ Large Format Printers
  • SC-T3270
  • SC-T5270
  • SC-T5270D
  • SC-T7270
  • SC-T7270D
  • SC-P6000
  • SC-P7000
  • SC-P8000
  • SC-P9000
  • SC-P10070
  • SC-P20070
▶ POS Printers
  • TM-H6000V
  • TM-m30
  • TM-m30II
  • TM-m30II-H
  • TM-m30II-NT
  • TM-m30II-S
  • TM-m30II-SL
  • TM-P20
  • TM-P80
  • TM-T81III
  • TM-T82III
  • TM-T82IIIL
  • TM-T82X
  • TM-T83III
  • TM-T88VI
  • TM-T88VI-iHUB