|
[Japanese]
|
JVNDB-2026-002119
|
Multiple vulnerabilities in BROTHER MFPs (multifunction printers)
|
Multiple MFPs provided by BROTHER INDUSTRIES, LTD. contain multiple vulnerabilities listed below.- Improper certificate validation (CWE-295) - CVE-2025-53869
- Hidden Functionality (CWE-912) - CVE-2025-55704
Anton Fabricius of SySS GmbH reported these vulnerabilities to the developer.
JPCERT/CC coordinated between the reporter and the developer.
|
CVSS V3 Severity: Base Metrics 5.3 (Medium) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: Low
- Integrity Impact: None
- Availability Impact: None
The above CVSS base scores have been assigned for CVE-2025-55704 |
CVSS v3 Severity Base Metrics:3.7 (Low) [Other]- Access Vector: Network
- Access Complexity: High
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): None
- Integrity Impact(I): Low
- Availability Impact(A): None
The above CVSS base scores have been assigned for CVE-2025-53869
|
As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed below.
|
KONICA MINOLTA, INC.
Brother Industries
Ricoh Co., Ltd
|
|
- The set of root certificates used by the product may be replaced with a set of arbitrary certificates by a man-in-the-middle attack (CVE-2025-53869)
- An attacker may obtain the logs of the affected product and obtain sensitive information within the logs (CVE-2025-55704)
|
[Update the firmware]
Apply the appropriate firmware update according to the information provided by the respective vendors.
For the details of the updates, refer to the information provided by the respective vendors listed on [Vendor Status] section.
|
KONICA MINOLTA, INC.
Brother Industries
Ricoh Co., Ltd
|
- Improper Certificate Validation(CWE-295) [Other]
- Hidden Functionality(CWE-912) [Other]
|
- CVE-2025-53869
- CVE-2025-55704
|
- JVN : JVNVU#92878805
|
- [2026/01/30]
Web page was published
|