Impact
A path traversal flaw exists in the web management interface of a wide range of Fujifilm Apeos multifunction devices and printers. The flaw arises from improper handling of externally supplied parameters, allowing an attacker to craft requests that reference files outside the intended directory. If successful, the attacker could read arbitrary files on the device, potentially revealing configuration data or credentials, and may be able to upload or execute malicious code through the same interface.
Affected Systems
Affected appliances include numerous Fujifilm Apeos models such as C4571, C3567, and many others listed in the CNA vendors products. The issue is present in firmware versions 1.1.3 and earlier across a broad spectrum of device models, including Japan, Asia Pacific, and European variants. Specific product line names and regional model variants are enumerated in the CNA list; the official advisory does not narrow the vulnerability to a single device but covers all listed models.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate risk with substantial potential impact on confidentiality and integrity. EPSS data is not available, but the lack of a CISA KEV listing suggests no active exploitation has been documented. The attack vector is most likely remote over the network that can reach the web interface, making it a high-priority concern for devices exposed to external or enterprise networks. If an attacker gains the ability to traverse directories, they could compromise the device, leading to further compromise of connected systems.
OpenCVE Enrichment