[Japanese]

JVNDB-2026-002119

Multiple vulnerabilities in BROTHER MFPs (multifunction printers)

Overview

Multiple MFPs provided by BROTHER INDUSTRIES, LTD. contain multiple vulnerabilities listed below.
  • Improper certificate validation (CWE-295) - CVE-2025-53869
  • Hidden Functionality (CWE-912) - CVE-2025-55704
Anton Fabricius of SySS GmbH reported these vulnerabilities to the developer.
JPCERT/CC coordinated between the reporter and the developer.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.3 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
The above CVSS base scores have been assigned for CVE-2025-55704


CVSS v3 Severity
Base Metrics:3.7 (Low) [Other]
  • Access Vector: Network
  • Access Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact(C): None
  • Integrity Impact(I): Low
  • Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2025-53869
Affected Products

As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed below.

KONICA MINOLTA, INC.
  • (Multiple Products)
Brother Industries
  • (Multiple Products)
Ricoh Co., Ltd
  • (multiple product)

Impact

  • The set of root certificates used by the product may be replaced with a set of arbitrary certificates by a man-in-the-middle attack (CVE-2025-53869)
  • An attacker may obtain the logs of the affected product and obtain sensitive information within the logs (CVE-2025-55704)
Solution

[Update the firmware]
Apply the appropriate firmware update according to the information provided by the respective vendors.
For the details of the updates, refer to the information provided by the respective vendors listed on [Vendor Status] section.
Vendor Information

KONICA MINOLTA, INC. Brother Industries Ricoh Co., Ltd
CWE (What is CWE?)

  1. Improper Certificate Validation(CWE-295) [Other]
  2. Hidden Functionality(CWE-912) [Other]
CVE (What is CVE?)

  1. CVE-2025-53869
  2. CVE-2025-55704
References

  1. JVN : JVNVU#92878805
Revision History

  • [2026/01/30]
      Web page was published