Impact
An attacker who can locate an Epson ED‑TW5350 projector equipped with the iProjection feature can gain access using a hard‑coded authentication string bundled with the Epson iProjection.apk v3.2.6. Once authenticated, the attacker can issue arbitrary control commands to the projector, potentially turning the device on or off, changing display settings, or streaming content without the owner’s knowledge. The vulnerability directly enables remote manipulation of the device because the credentials bypass any local user authentication layer.
Affected Systems
Epson EH‑TW5350 projector models that run the Epson iProjection.apk version 3.2.6.
Risk and Exploitability
The CVSS score of 9.8 and EPSS probability of < 1% highlight the vulnerability’s severe potential. The presence of hard‑coded credentials suggests a high risk of exploitation once an attacker locates the device. Even without a publicly disclosed exploit, the ability to authenticate via a known credential pair implies that the attack could be performed by an individual with network or physical proximity to the projector. The vulnerability is not listed in the CISA KEV catalog, but the lack of mitigation information indicates that the use of default credentials remains a significant threat vector.
OpenCVE Enrichment