Executive brief
The Epson EH-TW5350 projector's Web Control interface is used to manage the device remotely via the iProjection mobile app. An unauthenticated attacker on the same network can bypass security controls and execute privileged commands such as powering the projector on/off, switching inputs, adjusting volume, and accessing administrative settings—causing disruption to presentations or unauthorized device manipulation without needing valid credentials.
Technical details
This is an authentication bypass vulnerability (CWE-287) in the Epson EH-TW5350 projector's Web Control HTTP interface. The root cause is inconsistent enforcement of WWW-Authenticate (HTTP Basic) security: while normal Web Control page routes enforce authentication, specific /cgi-bin/ action endpoints (directsend and webconf) used by the iProjection companion application do not independently verify session or credentials before executing commands. An unauthenticated attacker on the same network can send specially crafted HTTP GET requests to these endpoints—no user interaction or physical access required—to power the device on/off, switch input sources, mute/control volume, or reach the administrative master page. The vulnerability affects firmware version 150075647YWWV110; remediation requires uniform authentication enforcement across all /cgi-bin/ endpoints.
Affected products
- Epson EH-TW5350 150075647YWWV110
Timeline
- 2021-11: disclosed: Discovered by B-BEAM-BOB during KITRI Best of the Best program
- 2021: other: Reported to Epson
- 2021-12-21: advisory: CVE-2021-43718 assigned by MITRE
- 2026-08-18: other: CVE published to CVE List; public advisory released