Description
Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the vulnerability allows an attacker to install firmware on an Epson projector without passing the normal verification checks. Based on the description, it is inferred that an unauthorized file can be fed to the system and installed, potentially modifying the firmware’s behavior or inserting malicious code. Based on the description, it is inferred that this breach would give the attacker full control over the projector’s firmware, affecting confidentiality, integrity, and availability of the device’s functions.

Affected Systems

The flaw is present in Epson EasyMP Network Updater version 1.20 for the projector series 150075647YWWV110. Devices using this firmware are directly susceptible to an unauthorized firmware upgrade when a USB connection is used.

Risk and Exploitability

The CVSS score is 9.8, indicating critical severity, while the EPSS score is under 1%, implying a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, limiting publicly known exploitation data. Based on the description, the attack surface appears to be local, relying on an attacker having physical access to attach a USB device. Based on the description, it is inferred that a repeatable attack vector exists if an attacker can supply a crafted firmware image. Given the available metrics, organizations should treat this as a high‑risk local vulnerability until a vendor patch is released.

Generated by OpenCVE AI on August 22, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Epson’s support site for an updated firmware version that addresses this issue.
  • Apply the latest firmware update after verifying its authenticity.
  • Disable the USB update functionality on the projector if not required for operation.
  • Contact Epson support for official guidance or a confirmed fix.

Generated by OpenCVE AI on August 22, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Epson
Epson easymp Network Updater
Vendors & Products Epson
Epson easymp Network Updater

Fri, 21 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Verification Bypass in Epson EasyMP Network Updater Enabling Unauthorized Firmware Updates via USB
Weaknesses CWE-285

Fri, 21 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-347
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Verification Bypass in Epson EasyMP Network Updater Enabling Unauthorized Firmware Updates via USB
Weaknesses CWE-285

Tue, 18 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.
References

Subscriptions

Epson Easymp Network Updater
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-21T20:18:56.777Z

Reserved: 2021-11-15T00:00:00.000Z

Link: CVE-2021-43716

cve-icon Vulnrichment

Updated: 2026-08-21T20:18:51.972Z

cve-icon NVD

Status : Received

Published: 2026-08-18T18:17:25.047

Modified: 2026-08-21T21:16:53.207

Link: CVE-2021-43716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:12:37Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature