Description
Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This flaw in Kyocera Command Center RX printers lets an attacker bypass the device’s encryption checks and export the entire address‑book, exposing passwords and other sensitive information. The vulnerability is an information‑exposure weakness (CWE‑200) combined with improper access control (CWE‑284) and insufficient encryption strength (CWE‑311, CWE‑326). An adversary who gains network reach to the printer can trigger a book export and obtain data that is normally protected by encryption.

Affected Systems

Kyocera Command Center RX Taskalfa printers, specifically models 2552ci, 3252ci, 2553ci, 3253ci, 3554ci, 4052ci, 5052ci, 6052ci, 7052ci, 8052ci, 7353ci, 8353ci, 2554ci, 3254ci and 505, with no specific firmware version information provided.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely exploitation path is a network‑based attack where an attacker sends a specially crafted request to the printer’s management interface to override encryption checks and trigger an export. Minimal authentication or unrestricted remote management could lower the effort required for a successful attack.

Generated by OpenCVE AI on July 26, 2026 at 16:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check Kyocera's website for a firmware or software update that addresses this issue, and apply it when available.
  • Restrict network connectivity to affected printers by implementing ACLs or firewall rules that limit access to trusted management stations only, and enforce role‑based access control so that only authorized personnel can export data.
  • Require strong authentication for any remote or local interface that interacts with the printer and ensure stored credentials are encrypted.

Generated by OpenCVE AI on July 26, 2026 at 16:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 26 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Kyocera Printer Vulnerability Allows Unauthorized Address‑Book Export

Thu, 23 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Kyocera Printer Encryption Bypass Enabling Sensitive Address Book Export

Tue, 21 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Kyocera Printer Encryption Bypass Enabling Sensitive Address Book Export

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Unauthorized Address Book Export via Encryption Bypass in Kyocera Command Center RX Printers

Mon, 13 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Address Book Export via Encryption Bypass in Kyocera Command Center RX Printers

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Bypassed Encryption in Kyocera Command Center RX Printers

Fri, 10 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Bypassed Encryption in Kyocera Command Center RX Printers

Fri, 10 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Kyocera
Kyocera command Center Rx
Vendors & Products Kyocera
Kyocera command Center Rx

Thu, 09 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200
CWE-284
CWE-311
CWE-326
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Unauthorized use of Kyocera printers, allows all information stored in the Kyocera address book to be exported. The security measure that encrypts incoming data ian be bypassed with this vulnerability, allowing encrypted data to be decrypted. Passwords and other sensitive information can be obtained. This affects Kyocera Command Center RX TASKalfa 2552ci, TASKalfa 3252ci, TASKalfa 2553ci, TASKalfa 3253ci, TASKalfa 3554ci, TASKalfa 4052ci, TASKalfa 5052ci, TASKalfa 6052ci, TASKalfa 7052ci, TASKalfa 8052ci, TASKalfa 7353ci, TASKalfa 8353ci, TASKalfa 2554ci, TASKalfa 3254ci, TASKalfa 505.
References

Subscriptions

Kyocera Command Center Rx
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-09T19:45:11.618Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63579

cve-icon Vulnrichment

Updated: 2026-07-09T19:45:07.468Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:15:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control

  • CWE-311

    Missing Encryption of Sensitive Data

  • CWE-326

    Inadequate Encryption Strength