Command Execution Vulnerability in Epson WebConfig

Vulnerability Reference: CVE-2025-6635

Description: An administrator password is required to log in to WebConfig. A malicious third party who obtains the administrator password can execute arbitrary commands by logging in to Web Config and entering a specific string on a specific screen.

Impact: The product settings could be reset or ping packets could be sent to other devices. There have been no reports of attacks exploiting this vulnerability to date.

Solution: We strongly recommend applying a fixed firmware or taking workaround to mitigate the impact of this vulnerability.

  • Apply fixed firmware
    For products that are currently on sale, we have released fixed firmware as listed below. Please download it from the Epson website and apply the update.
     
  • Take workaround
    To ensure the security of your Epson product, we recommend end-users and their administrators to implement and maintain industry-standard security controls and practices in setting up and managing password and network to which the product is connected.
    • Administator Password
      • Please set a unique password for each product.
      • The administator password should be a complex string of characters that is difficult for others to guess, such as eight or more characters that contain not only English letters but also symbols and numbers.
    • Internet Connection
      • Do not connect the product directly to the Internet; install it within a network protected by a firewall.
      • Please set a private IP address for the product.

 

For more information on securing your Epson product, please refer to the "Security Guidelines" on the Security for Printers and MFPs website.

Affected Models

Model Solution
SureColor P10000Fixed Firmware
SureColor P10050Fixed Firmware
SureColor P10070Fixed Firmware
SureColor P10080Fixed Firmware
SureColor P10080DFixed Firmware
SureColor P20000Fixed Firmware
SureColor P20050Fixed Firmware
SureColor P20070Fixed Firmware
SureColor P20080Fixed Firmware
SureColor P6000Fixed Firmware
SureColor P6050Fixed Firmware
SureColor P6070Fixed Firmware
SureColor P6080Fixed Firmware
SureColor P7000Fixed Firmware
SureColor P7050Fixed Firmware
SureColor P7070Fixed Firmware
SureColor P7080Fixed Firmware
SureColor P8000Fixed Firmware
SureColor P8050Fixed Firmware
SureColor P8070Fixed Firmware
SureColor P8080Fixed Firmware
SureColor P9000Fixed Firmware
SureColor P9050Fixed Firmware
SureColor P9070Fixed Firmware
SureColor P9080Fixed Firmware
SureColor T3200Fixed Firmware
SureColor T3250Fixed Firmware
SureColor T3255Fixed Firmware
SureColor T3270Fixed Firmware
SureColor T3280Fixed Firmware
SureColor T5200Fixed Firmware
SureColor T5200DFixed Firmware
SureColor T5250Fixed Firmware
SureColor T5250DFixed Firmware
SureColor T5255Fixed Firmware
SureColor T5255DFixed Firmware
SureColor T5270Fixed Firmware
SureColor T5270DFixed Firmware
SureColor T5280Fixed Firmware
SureColor T5280DFixed Firmware
SureColor T7200Fixed Firmware
SureColor T7200DFixed Firmware
SureColor T7250Fixed Firmware
SureColor T7250DFixed Firmware
SureColor T7255Fixed Firmware
SureColor T7255DFixed Firmware
SureColor T7270Fixed Firmware
SureColor T7270DFixed Firmware
SureColor T7280Fixed Firmware
SureColor T7280DFixed Firmware
Model Solution
TM-H6000VFixed firmware
TM-L100Fixed firmware
TM-m10Fixed firmware
TM-m30Fixed firmware
TM-m30IIFixed firmware
TM-m30II-HFixed firmware
TM-m30II-NTFixed firmware
TM-m30II-SFixed firmware
TM-m30II-SLFixed firmware
TM-m50Fixed firmware
TM-P20Workaround
TM-P60IIWorkaround
TM-P80Workaround
TM-T20II(**7)Workaround
TM-T20IIIFixed firmware
TM-T20IIILFixed firmware
TM-T20XFixed firmware
TM-T81IIIFixed firmware
TM-T82IIIFixed firmware
TM-T82IIILFixed firmware
TM-T82XFixed firmware
TM-T83IIIFixed firmware
TM-T88VIFixed firmware
TM-T88VI-iHUBFixed firmware
TM-T100EFixed firmware
TM-T100MFixed firmware
TM-T100NFixed firmware
TM-T100SFixed firmware
TM-T100WFixed firmware
UB-E04Fixed firmware
UB-R04Workaround
UB-R05Fixed firmware