Impact
A CSRF vulnerability in SEIKO EPSON Web Config allows an attacker to trick a logged‑in user into visiting a malicious page, causing the browser to submit privileged requests without the user’s consent. This flaw, identified as CWE-352, can result in unauthorized configuration changes or function executions on the affected device. Based on the description, it is inferred that the attacker must have an authenticated session to exploit this vulnerability.
Affected Systems
SEIKO EPSON Web Config is affected; the advisory does not list specific build or firmware numbers, so all released versions are considered vulnerable until vendor guidance is provided.
Risk and Exploitability
The CVSS v3.1 score of 5.1 indicates moderate severity, while the EPSS score of < 1% suggests a low likelihood of exploitation. Based on the description, it is inferred that an attacker must have an authenticated session and convince a user to load a malicious page, which limits the attack surface and suggests the threat is moderate but worth monitoring.
OpenCVE Enrichment