Impact
Based on the description, it is inferred that the vulnerability allows an attacker to install firmware on an Epson projector without passing the normal verification checks. Based on the description, it is inferred that an unauthorized file can be fed to the system and installed, potentially modifying the firmware’s behavior or inserting malicious code. Based on the description, it is inferred that this breach would give the attacker full control over the projector’s firmware, affecting confidentiality, integrity, and availability of the device’s functions.
Affected Systems
The flaw is present in Epson EasyMP Network Updater version 1.20 for the projector series 150075647YWWV110. Devices using this firmware are directly susceptible to an unauthorized firmware upgrade when a USB connection is used.
Risk and Exploitability
The CVSS score is 9.8, indicating critical severity, while the EPSS score is under 1%, implying a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog, limiting publicly known exploitation data. Based on the description, the attack surface appears to be local, relying on an attacker having physical access to attach a USB device. Based on the description, it is inferred that a repeatable attack vector exists if an attacker can supply a crafted firmware image. Given the available metrics, organizations should treat this as a high‑risk local vulnerability until a vendor patch is released.
OpenCVE Enrichment