[Japanese]

JVNDB-2026-029323

Multiple SEIKO EPSON printers and scanners keep already revoked root certificates

Overview

Multiple printers and scanners provided by SEIKO EPSON CORPORATION contain the following vulnerability.
  • Remaining revoked root certificates (CWE-296) - CVE-2026-73542
Agni Athreya, CyberArch Student Researcher of Carl Vinson Institute of Government at University of Georgia reported this vulnerability to SEIKO EPSON CORPORATION and coordinated. After the coordination was completed, SEIKO EPSON CORPORATION reported the case to JPCERT/CC to notify users of the solution through JVN.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 3.7 (Low) [Other]
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


SEIKO EPSON CORPORATION
  • (Multiple Products)

A wide range of products are affected.
For more details, refer to the information provided by the developer.
Impact

A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product.
Solution

[Update the root certificates]
Update the root certificates in the product according to the information provided by the developer.
Vendor Information

SEIKO EPSON CORPORATION
CWE (What is CWE?)

  1. Improper Following of a Certificate's Chain of Trust(CWE-296) [Other]
CVE (What is CVE?)

  1. CVE-2026-73542
References

  1. JVN : JVNVU#91609598
Revision History

  • [2026/08/21]
      Web page was published