Cross Site Scripting Vulnerability in Epson Web Configuration Page for AirPrint

 

Vulnerability Reference: CVE-2018-5550

Release Date: January 19, 2018

Description:
 Epson has become aware of a vulnerability related to Epson’s web configuration page for AirPrint in certain Epson printer products.

Impact: This vulnerability may compromise the security of the printer’s web browser through the injection of malicious code or scripts.

Solution: Epson periodically provides firmware updates to address issues of security, performance, minor bug fixes, and to ensure your printer functions as designed. To update your printer’s firmware, run the Epson Software Updater utility and follow the step-by-step instructions. If your printer’s firmware isn't yet available (see schedule below), this utility will automatically notify you when it becomes available. Please visit our Updating your Printer's Firmware Using Epson Software Updater page for additional information.

If you haven’t already installed the Epson Software Updater utility, you can download it here.

In the meantime, and as a general rule to help secure all devices, end-users and their administrators should always implement and maintain industry-standard security controls and practices in setting up and managing their networks. Those practices include immediately replacing default passwords with strong passwords, use of up to date antivirus/malware protection, utilizing the strongest possible wireless encryption protocol and enabling appropriate firewall rules. Additionally, Epson always recommends that end users routinely check for software and firmware updates and keep their products updated to the latest software and firmware to achieve the best possible performance from their products.

Model Name

Status

ET-2550 Available Now
ET-2650 Available Now
ET-3600 Available Now
ET-4500 Available Now
ET-4550 Available Now
ET-7700 Available Now
PictureMate PM 400 Available Now
WF-100 Available Now
WF-2630 Available Now
WF-2650 Available Now
WF-2660 Available Now
WF-2750 Available Now
WF-2760 Available Now
WF-3620 Available Now
WF-3640 Available Now
WF-4630 Available Now
WF-4640 Available Now
WF-5110 Available Now
WF-5190 Available Now
WF-5620 Available Now
WF-5690 Available Now
WF-6090 Available Now
WF-6530 Available Now
WF-7110 Available Now
WF-7610 Available Now
WF-7620 Available Now
WF-8090 Available Now
WF-8590 Available Now
WF-M5190 Available Now
WF-M5690 Available Now
WF-R4640 Available Now
WF-R5190 Available Now
WF-R5690 Available Now
WF-R8590 Available Now
XP-310 Available Now
XP-320 Available Now
XP-330 Available Now
XP-340 Available Now
XP-410 Available Now
XP-420 Available Now
XP-424 Available Now
XP-430 Available Now
XP-434 Available Now
XP-440 Available Now
XP-446 Available Now
XP-520 Available Now
XP-530 Available Now
XP-610 Available Now
XP-620 Available Now
XP-630 Available Now
XP-640 Available Now
XP-810 Available Now
XP-820 Available Now
XP-830 Available Now
XP-860 Available Now
XP-950 Available Now
XP-960 Available Now