CRITICAL🇵🇱 Wersja polska

CVE-2026-23767

CVSS 9.8v3.1pub. 2026-03-05upd. 2026-03-09

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.

🤖 AI Analysis
How it works

The ESC/POS protocol does not require any authentication before accepting and executing control commands. The lack of authorization mechanisms means that any entity able to establish a network connection to the device can send any commands. Data transmission occurs without encryption and without data integrity verification, which additionally enables eavesdropping and command modification. The protocol also does not provide any controls limiting the sources or destinations of network communication.

Impact

An unauthenticated remote attacker can gain full control over the device — read, modify or block its operation, and potentially compromise the confidentiality, integrity and availability of processed data.

Mitigation & patch

Patches available from the manufacturer should be applied according to references. Additionally, the manufacturer provides an IP Filtering Guide that should be implemented to restrict network access to devices to trusted hosts only. Devices should not be directly accessible from public networks — network segmentation and firewall rules should be applied.

Who is affected

Epson devices: UB-R04, UB-E04 (firmware), UB-E04, SB-H50 (firmware), SB-H50 — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Epson Sb H50

    HW
    Epson
    all versions
  • Epson Sb H50 Firmware

    OS
    Epson
    all versions
  • Epson Tm H6000v

    HW
    Epson
    all versions
  • Epson Tm H6000v Firmware

    OS
    Epson
    all versions
  • Epson Tm L100

    HW
    Epson
    all versions
  • Epson Tm L100 Firmware

    OS
    Epson
    all versions
  • Epson Tm M10

    HW
    Epson
    all versions
  • Epson Tm M10 Firmware

    OS
    Epson
    all versions
  • Epson Tm M30

    HW
    Epson
    all versions
  • Epson Tm M30 Firmware

    OS
    Epson
    all versions
  • Epson Tm M30ii

    HW
    Epson
    all versions
  • Epson Tm M30ii Firmware

    OS
    Epson
    all versions
  • Epson Tm M30ii H

    HW
    Epson
    all versions
  • Epson Tm M30ii H Firmware

    OS
    Epson
    all versions
  • Epson Tm M30iii

    HW
    Epson
    all versions
  • Epson Tm M30iii Firmware

    OS
    Epson
    all versions
  • Epson Tm M30iii H

    HW
    Epson
    all versions
  • Epson Tm M30iii H Firmware

    OS
    Epson
    all versions
  • Epson Tm M30ii S

    HW
    Epson
    all versions
  • Epson Tm M30ii S Firmware

    OS
    Epson
    all versions
  • Epson Tm M30ii Sl

    HW
    Epson
    all versions
  • Epson Tm M30ii Sl Firmware

    OS
    Epson
    all versions
  • Epson Tm M55

    HW
    Epson
    all versions
  • Epson Tm M55 Firmware

    OS
    Epson
    all versions
  • Epson Tm P20

    HW
    Epson
    all versions
  • Epson Tm P20 Firmware

    OS
    Epson
    all versions
  • Epson Tm P20ii

    HW
    Epson
    all versions
  • Epson Tm P20ii Firmware

    OS
    Epson
    all versions
  • Epson Tm P60ii

    HW
    Epson
    all versions
  • Epson Tm P60ii Firmware

    OS
    Epson
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-36133CRITICAL9.1PL ✓same vendor

Pominięcie uwierzytelnienia w WebConfig urządzeń Epson TM-C3500/TM-C7500

CVE-2020-28929CRITICAL9.8PL ✓same vendor

EPSON EPS TSE Server 8 — nieautoryzowany dostęp do poświadczeń administratora

CVE-2020-6091CRITICAL9.1PL ✓same vendor

Pominięcie uwierzytelniania w EPSON Web Control (Epson EB-1470Ui)

CVE-2018-19248CRITICAL9.1PL ✓same vendor

Epson WorkForce WF-2861 — wgranie firmware bez uwierzytelnienia

CVE-2017-12860CRITICAL9.8PL ✓same vendor

Epson EasyMP — zakodowany na stałe kod backdoor umożliwiający nieautoryzowany dostęp