CVE-2026-23767

CRITICALCVSS 9.8/10EPSS 0.45%

Last modified

CVE-2026-23767 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.. EPSS estimates a 0.45% chance of exploitation in the next 30 days.

Description

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.45%

35.7th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
EpsonSb-H50 FirmwareAll versions
EpsonTm-H6000v FirmwareAll versions
EpsonTm-L100 FirmwareAll versions
EpsonTm-M10 FirmwareAll versions
EpsonTm-M30 FirmwareAll versions
EpsonTm-M30ii FirmwareAll versions
EpsonTm-M30ii-H FirmwareAll versions
EpsonTm-M30ii-S FirmwareAll versions
EpsonTm-M30ii-Sl FirmwareAll versions
EpsonTm-M30iii FirmwareAll versions
EpsonTm-M30iii-H FirmwareAll versions
EpsonTm-M55 FirmwareAll versions
EpsonTm-P20ii FirmwareAll versions
EpsonTm-P80ii FirmwareAll versions
EpsonTm-P20 FirmwareAll versions
EpsonTm-P60ii FirmwareAll versions
EpsonTm-P80 FirmwareAll versions
EpsonTm-T20ii FirmwareAll versions
EpsonTm-T20iii FirmwareAll versions
EpsonTm-T88vi FirmwareAll versions
EpsonTm-T88vi-Ihub FirmwareAll versions
EpsonTm-T88vii FirmwareAll versions
EpsonUb-R04 FirmwareAll versions
EpsonUb-E04 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2026-23767?
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.
How severe is CVE-2026-23767?
CVE-2026-23767 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 0.45% probability of exploitation in the next 30 days.
How do I fix CVE-2026-23767?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2026-23767?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST