Impact
This flaw in Kyocera Command Center RX printers lets an attacker bypass the device’s encryption checks and export the entire address‑book, exposing passwords and other sensitive information. The vulnerability is an information‑exposure weakness (CWE‑200) combined with improper access control (CWE‑284) and insufficient encryption strength (CWE‑311, CWE‑326). An adversary who gains network reach to the printer can trigger a book export and obtain data that is normally protected by encryption.
Affected Systems
Kyocera Command Center RX Taskalfa printers, specifically models 2552ci, 3252ci, 2553ci, 3253ci, 3554ci, 4052ci, 5052ci, 6052ci, 7052ci, 8052ci, 7353ci, 8353ci, 2554ci, 3254ci and 505, with no specific firmware version information provided.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of <1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely exploitation path is a network‑based attack where an attacker sends a specially crafted request to the printer’s management interface to override encryption checks and trigger an export. Minimal authentication or unrestricted remote management could lower the effort required for a successful attack.
OpenCVE Enrichment