• Privacy Policy
  • Contact Us
星期三, 10 6 月, 2026
  • Home
  • Smartphone Reviews
  • Tech & Tools Reviews
  • Hardware Reviews
  • Contact Us
  • Privacy Policy
No Result
View All Result
  • Home
  • Smartphone Reviews
  • Tech & Tools Reviews
  • Hardware Reviews
  • Contact Us
  • Privacy Policy
No Result
View All Result
readtoprofit
No Result
View All Result
Home Gadget Rankings

689 different Brother printer models all use the serial number to create default password — ridiculous security flaw baked in from manufacturing, can’t be fully remediated with firmware

TwoCat by TwoCat
28 6 月, 2025
in Gadget Rankings
0
689 different Brother printer models all use the serial number to create default password — ridiculous security flaw baked in from manufacturing, can’t be fully remediated with firmware
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

Another reminder to change your devices’ default passwords has arrived, thanks to a new critical vulnerability found in Brother printers. 689 different models of Brother printers, plus a handful of other printers from Fujifilm, Toshiba, and Konica Minolta, are susceptible to eight new security vulnerabilities, some of which cannot be patched with firmware updates.

Security company Rapid7 discovered the exploits in a recent investigation of some Brother printers. The most severe of these, CVE-2024-51978, given a 9.8 Critical rating, allows attackers to generate the device’s default admin password. The affected models have default passwords created algorithmically using their serial numbers as a seed, so attackers with the printer’s serial number (accessible via HTTP thanks to CVE-2024-51977) can create the default password and access the printer and the rest of the network.

Related articles

Experts recommend the ‘caveman method’ for keeping your house cool in a heatwave — here’s how it works

Experts recommend the ‘caveman method’ for keeping your house cool in a heatwave — here’s how it works

28 6 月, 2025
Anker’s 3D texture printer raises  million in most successful Kickstarter campaign ever — world’s first UV printer for personal use to begin shipping in August

Anker’s 3D texture printer raises $45 million in most successful Kickstarter campaign ever — world’s first UV printer for personal use to begin shipping in August

28 6 月, 2025

The other vulnerabilities opened up by this attack vector include the ability to trigger a buffer overflow and achieve remote code execution, forcing the device to open connections across the network, exposing the passwords for other network services like LDAP or FTP, and repeatedly crashing the printer, rendering it inoperable, among others.


You may like

Swipe to scroll horizontally

CVE

Description

CVSS

CVE-2024-51977

An unauthenticated attacker can leak sensitive information.

5.3 (Medium)

CVE-2024-51978

An unauthenticated attacker can generate the device’s default administrator password.

9.8 (Critical)

CVE-2024-51979

An authenticated attacker can trigger a stack based buffer overflow.

7.2 (High)

CVE-2024-51980

An unauthenticated attacker can force the device to open a TCP connection.

5.3 (Medium)

CVE-2024-51981

An unauthenticated attacker can force the device to perform an arbitrary HTTP request.

5.3 (Medium)

CVE-2024-51982

An unauthenticated attacker can crash the device.

7.5 (High)

CVE-2024-51983

An unauthenticated attacker can crash the device.

7.5 (High)

CVE-2024-51984

An authenticated attacker can disclose the password of a configured external service.

6.8 (Medium)

The most severe vulnerability, the password generation flaw, is something that is determined at the time of the printer’s manufacturing, meaning that it cannot be fixed with firmware updates. Brother confirmed this fact in a statement to Rapid7, with its product advisory pages guiding customers to change their printer’s password to a new one, and to update their printer firmware to protect against the other flaws. We’ve seen some security flaws in our time, but generating a password using a device’s serial number is right up there.

Not every flaw is found on every printer model from the four manufacturers, with the main CVE-2024-51978 and CVE-2024-51980 being the most common. Thankfully, the CVE-2024-51977 vulnerability that opens up the printer to having its serial number remotely accessible is among the least common vulnerabilities, with only 463 of the 748 total models affected.

While most readers of Tom’s Hardware are surely aware of the need to change their network-connected devices’ default passwords shortly after setup, many less knowledgeable users are prone to leaving default passwords unchanged, which in this case could lead to having their printers crashed by trolls on the internet, or perhaps worse. So let this disclosure act as a sage reminder to update your default passwords, or else. A full summary of all of the vulnerabilities and what attacks they open up is available on Rapid7’s disclosure site.

Follow Tom’s Hardware on Google News to get our up-to-date news, analysis, and reviews in your feeds. Make sure to click the Follow button.

Get Tom’s Hardware’s best news and in-depth reviews, straight to your inbox.

🔗 Source: www.tomshardware.com

Share76Tweet47

Related Posts

Experts recommend the ‘caveman method’ for keeping your house cool in a heatwave — here’s how it works

Experts recommend the ‘caveman method’ for keeping your house cool in a heatwave — here’s how it works

by TwoCat
28 6 月, 2025
0

When summer arrives,...

Anker’s 3D texture printer raises  million in most successful Kickstarter campaign ever — world’s first UV printer for personal use to begin shipping in August

Anker’s 3D texture printer raises $45 million in most successful Kickstarter campaign ever — world’s first UV printer for personal use to begin shipping in August

by TwoCat
28 6 月, 2025
0

It was just a few mo...

Asus’s new BTF GPUs can now be used in standard systems courtesy of a detachable 1000W power connector — New 5090 and RTX 5070 Ti models have a dual personality

Asus’s new BTF GPUs can now be used in standard systems courtesy of a detachable 1000W power connector — New 5090 and RTX 5070 Ti models have a dual personality

by TwoCat
28 6 月, 2025
0

Asus has announced i...

SpaceX launches UK satellite to create semiconductors in low Earth orbit — sub-zero temps and vacuum of space could advance AI data centers and quantum computing

SpaceX launches UK satellite to create semiconductors in low Earth orbit — sub-zero temps and vacuum of space could advance AI data centers and quantum computing

by TwoCat
28 6 月, 2025
0

Manufacturing advanc...

I’ve tried all the leading AI chatbots — here’s why I keep going back to Claude

I’ve tried all the leading AI chatbots — here’s why I keep going back to Claude

by TwoCat
28 6 月, 2025
0

I've tried all the l...

Load More

Recent News

Samsung Galaxy A55 spotted on Geekbench running Android 16, could get One UI 8 before next year| Tech News

Samsung Galaxy A55 spotted on Geekbench running Android 16, could get One UI 8 before next year| Tech News

29 6 月, 2025
How to watch Noah Kahan at Glastonbury 2025 for FREE

How to watch Noah Kahan at Glastonbury 2025 for FREE

29 6 月, 2025

分类

  • Gadget Rankings
  • Hardware Reviews
  • Smartphone Reviews
  • Tech & Tools Reviews
No Result
View All Result
  • Contact Us
  • Homepages

© 2025 ReadToProfit. All rights reserved.