Description
An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously.
Published: 2026-08-18
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker who can locate an Epson ED‑TW5350 projector equipped with the iProjection feature can gain access using a hard‑coded authentication string bundled with the Epson iProjection.apk v3.2.6. Once authenticated, the attacker can issue arbitrary control commands to the projector, potentially turning the device on or off, changing display settings, or streaming content without the owner’s knowledge. The vulnerability directly enables remote manipulation of the device because the credentials bypass any local user authentication layer.

Affected Systems

Epson EH‑TW5350 projector models that run the Epson iProjection.apk version 3.2.6.

Risk and Exploitability

The CVSS score of 9.8 and EPSS probability of < 1% highlight the vulnerability’s severe potential. The presence of hard‑coded credentials suggests a high risk of exploitation once an attacker locates the device. Even without a publicly disclosed exploit, the ability to authenticate via a known credential pair implies that the attack could be performed by an individual with network or physical proximity to the projector. The vulnerability is not listed in the CISA KEV catalog, but the lack of mitigation information indicates that the use of default credentials remains a significant threat vector.

Generated by OpenCVE AI on August 21, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Epson iProjection appliance to a version that removes hard‑coded credentials; contact Epson for the latest firmware or software patch.
  • If an update is unavailable, disable the iProjection feature via the projector’s administrative interface or permanently block network access to the device using access control lists or firewall rules.
  • Restrict network segments accessed by the projector and monitor for anomalous authentication attempts, ensuring any compromise is detected promptly.

Generated by OpenCVE AI on August 21, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Hard‑coded credentials allow remote control of Epson iProjection projector

Fri, 21 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Epson
Epson iprojection
Vendors & Products Epson
Epson iprojection

Tue, 18 Aug 2026 20:15:00 +0000

Type Values Removed Values Added
Title Hard‑coded credentials allow remote control of Epson iProjection projector
Weaknesses CWE-798

Tue, 18 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the projector using hard-coded authentication information and control the projector maliciously.
References

Subscriptions

Epson Iprojection
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-21T20:17:10.308Z

Reserved: 2021-11-15T00:00:00.000Z

Link: CVE-2021-43717

cve-icon Vulnrichment

Updated: 2026-08-21T20:17:05.650Z

cve-icon NVD

Status : Received

Published: 2026-08-18T18:17:26.013

Modified: 2026-08-21T21:16:53.400

Link: CVE-2021-43717

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T23:00:14Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials