Description
Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may be performed.
Published: 2026-07-07
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This CSRF flaw in SEIKO EPSON Web Config lets an attacker force a logged‑in user’s browser to submit privileged requests to the device without the user’s consent. The attacker can therefore alter configuration settings or trigger other state‑changing functions on the device. Because the attack requires an authenticated session, the impact is limited to users who are already logged in, but the allowed operations could lead to a loss of service, incorrect device settings, or a gateway to further network compromise.

Affected Systems

The vulnerable component is SEIKO EPSON Web Config. No specific firmware or build numbers are provided, so all released versions are potentially affected until vendor guidance is issued.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the victim to be authenticated and to visit a malicious webpage, which limits the attack surface but still warrants monitoring.

Generated by OpenCVE AI on August 1, 2026 at 17:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any SEIKO EPSON firmware or Web Config patch that addresses CVE‑2026‑58315 as soon as it is published.
  • Limit access to the Web Config interface to trusted network segments or VPN endpoints to reduce exposure to malicious web pages.
  • Configure the SameSite attribute on session cookies to 'Strict' or 'Lax' if supported by the application to mitigate unintended cross‑origin requests.
  • Enable logging of state‑changing requests and review logs regularly for unexpected activity.

Generated by OpenCVE AI on August 1, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in SEIKO EPSON Web Config allows unintended authenticated operations

Wed, 29 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in SEIKO EPSON Web Config allows unintended authenticated operations

Fri, 24 Jul 2026 18:30:00 +0000


Thu, 23 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in SEIKO EPSON Web Config Enables Privileged Operations

Thu, 16 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in SEIKO EPSON Web Config Enables Privileged Operations

Mon, 13 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in SEIKO EPSON Web Config Enables Unauthorized Operations

Sun, 12 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Cross‑Site Request Forgery in SEIKO EPSON Web Config Enables Unauthorized Operations

Sat, 11 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Web Config Cross‑Site Request Forgery Enabling Unintended Operations While Authenticated

Fri, 10 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Web Config Cross‑Site Request Forgery Enabling Unintended Operations While Authenticated

Thu, 09 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title CSRF Vulnerability in SEIKO EPSON Web Config Allows Unintended Operations

Wed, 08 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title CSRF Vulnerability in SEIKO EPSON Web Config Allows Unintended Operations

Wed, 08 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Unintended Operations via Cross‑Site Request Forgery in SEIKO EPSON Web Config

Tue, 07 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Unintended Operations via Cross‑Site Request Forgery in SEIKO EPSON Web Config

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description Cross-site request forgery vulnerability exists in SEIKO EPSON Web Config. If a user views a malicious page while logged into Web Config, unintended operations may be performed.
Weaknesses CWE-352
References
Metrics cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-07-24T09:15:32.321Z

Reserved: 2026-07-01T01:18:28.835Z

Link: CVE-2026-58315

cve-icon Vulnrichment

Updated: 2026-07-07T13:34:09.968Z

cve-icon NVD

Status : Deferred

Published: 2026-07-07T06:16:23.147

Modified: 2026-07-24T10:16:31.823

Link: CVE-2026-58315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T17:45:04Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)