Description
Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
Published: 2026-08-20
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises because several SEIKO EPSON printers and scanners ship with revoked root certificates. A compromised certificate enables an attacker engaged in a man‑in‑the‑middle attack to capture the data transmitted between the device and its client or server. The impact is loss of confidentiality of all data flowing through the affected device, but does not directly provide a path to execute code or modify device firmware.

Affected Systems

The flaw affects multiple SEIKO EPSON printers and scanners as listed by the vendor; specific models and firmware versions are detailed on Epson’s security advisory, but the set of affected devices includes both printers and scanners from SEIKO EPSON.

Risk and Exploitability

The CVSS score is 6.3, indicating a moderate severity. EPSS data is unavailable, so the exact exploitation probability is unknown. The flaw is not listed in CISA’s KEV catalog, suggesting no publicly documented exploits at this time. The likely attack vector is a hostile network segment that can intercept or inject traffic to the device; an attacker would need network access to the Ethernet or Wi‑Fi interface used by the device.

Generated by OpenCVE AI on August 20, 2026 at 07:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest firmware or security update from SEIKO EPSON that corrects the revoked root certificates
  • Configure the device or network elements to reject connections using root certificates that are listed as revoked
  • Ensure the device’s certificate validation logic enables revocation checks for SSL/TLS connections

Generated by OpenCVE AI on August 20, 2026 at 07:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Seiko Epson Corporation
Seiko Epson Corporation multiple Seiko Epson Printers And Scanners
Vendors & Products Seiko Epson Corporation
Seiko Epson Corporation multiple Seiko Epson Printers And Scanners

Thu, 20 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Title Revoked Root Certificates Enable Man‑in‑The‑Middle Data Capture on SEIKO EPSON Devices

Thu, 20 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Description Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.
Weaknesses CWE-296
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Seiko Epson Corporation Multiple Seiko Epson Printers And Scanners
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-20T15:26:27.771Z

Reserved: 2026-08-17T04:36:05.953Z

Link: CVE-2026-73542

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T06:17:13.287

Modified: 2026-08-28T16:09:10.947

Link: CVE-2026-73542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T09:07:29Z

Weaknesses
  • CWE-296

    Improper Following of a Certificate's Chain of Trust