Millions of Brother Printers Contain Vulnerable Exploits

0
12كيلو بايت

Brother makes some solid, reliable printers. Indeed, for several years running, The Verge named it the best printer you should buy. Unfortunately, the company’s devices appear to be riddled with new zero-day bugs that could allow a savvy cybercriminal to hijack them.

The vulnerabilities were discovered by cybersecurity firm Rapid7, which published a blog about the bugs last week. The blog explains that, after some research, Rapid7’s cyber pros came across a total of eight new zero-day vulnerabilities in the machines. The vulnerabilities are all different, though there is one that is pretty bad. CVE-2024-51978 is an authentication bypass vulnerability that could allow a hacker to nab the printer’s password. Researchers break it down like so:

A remote unauthenticated attacker can leak the target device’s serial number through one of several means, and in turn generate the target device’s default administrator password. This is due to the discovery of the default password generation procedure used by Brother devices. This procedure transforms a serial number into a default password. Affected devices have their default password set, based on each device’s unique serial number, during the manufacturing process. Brother has indicated that this vulnerability cannot be fully remediated in firmware, and has required a change to the manufacturing process of all affected models.

Researchers originally contacted Brother Industries last year, and the printing company and security researchers have been in touch since then, working to mitigate the issues. The bugs are also impacting several other printer brands, including FujifilmRicohToshiba, and Konica Minolta, according to researchers.  

Dark Reading notes that millions of devices appear to be impacted. Luckily, researchers note that there is no evidence that the bugs are being exploited in the wild. Brother has also issued patches for the vulnerabilities.

In addition to installing patches, users are also encouraged to change their default administrator password. That should stop the bad bug, CVE-2024-51978, which would have allowed an intruder to hijack the machine. If you don’t do that, researchers warn that an attacker could “use this default administrator password to either reconfigure the target device, or access functionality only intended for authenticated users.”

Gizmodo reached out to Brother Industries for more information. In a statement shared Wednesday, the company said: “Brother would like to thank Rapid7 for their efforts in discovering the issues. We have informed our customers about the mitigation on our website.”

Like
Love
Haha
3
البحث
الأقسام
إقرأ المزيد
News
Kể từ ngày 1/7, hàng hóa dịch vụ từ 5.000.000 đồng trở lên phải chú ý điều này, hàng triệu hộ kinh doanh nên nắm
Trong đó, chứng từ thanh toán không dùng tiền mặt là...
بواسطة CriticalSample7743 2025-07-12 03:33:04 0 9كيلو بايت
News
Ai sẽ bị khóa sim, thu hồi số điện thoại dù là chính chủ từ nay đến trước 1/8/2025? Nếu bị khóa cần phải làm gì?
Từ nay đến trước 1/8/2025, có 5 trường hợp số điện...
بواسطة ComfortableTutor43 2025-06-16 23:46:06 0 9كيلو بايت
Food
Garlic Parmesan Bacon Cheeseburger Bombs
Ingredients:- 1 lb ground beef- 1/2 cup grated parmesan cheese- 1/4 cup breadcrumbs- 2 cloves...
بواسطة MaiPham 2025-03-14 22:42:30 0 16كيلو بايت
News
Đặt 3 thứ này trên bàn thờ giúp xua đuổi vận xui, đón lộc Thần Tài
1. Hoa sen Hoa sen được mệnh danh là "quốc hoa" của...
بواسطة nikolinefrayOF 2025-07-08 10:06:04 0 9كيلو بايت
CỘNG ĐỒNG
Xoài Non và bạn mới công bố ý định "niềm vui" trên thảm đỏ Gala WeChoice Awards 2024.
Tối 12/1, Gala Vinh danh và Trao giải WeChoice Awards 2024 diễn ra tại Trung tâm Hội chợ và...
بواسطة norwood13_1XDi 2025-06-21 09:05:12 0 10كيلو بايت