An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00047}

epss

{'score': 0.00055}


Fri, 08 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Epson
Epson xp-255
Weaknesses CWE-276
CPEs cpe:2.3:h:epson:xp-255:*:*:*:*:*:*:*:*
Vendors & Products Epson
Epson xp-255
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 07 Nov 2024 18:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-11-08T16:43:08.103Z

Reserved: 2020-02-17T00:00:00

Link: CVE-2019-20458

cve-icon Vulnrichment

Updated: 2024-11-08T16:43:02.181Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-07T18:15:15.170

Modified: 2024-11-08T19:01:03.880

Link: CVE-2019-20458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.