Impact
This CSRF flaw in SEIKO EPSON Web Config lets an attacker force a logged‑in user’s browser to submit privileged requests to the device without the user’s consent. The attacker can therefore alter configuration settings or trigger other state‑changing functions on the device. Because the attack requires an authenticated session, the impact is limited to users who are already logged in, but the allowed operations could lead to a loss of service, incorrect device settings, or a gateway to further network compromise.
Affected Systems
The vulnerable component is SEIKO EPSON Web Config. No specific firmware or build numbers are provided, so all released versions are potentially affected until vendor guidance is issued.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the victim to be authenticated and to visit a malicious webpage, which limits the attack surface but still warrants monitoring.
OpenCVE Enrichment