Junglewise Threat Intelligence

CVE-2023-49367: Kyocera Command Center RX information disclosure in Address Book test function

CVE-2023-49367 · Severity: high · CVSS 8.8 · Published 2025-09-18

Executive brief

A security vulnerability exists in the web management interface of Kyocera M5521cdn printers. The interface, used by administrators to manage printer settings and address books, transmits sensitive credentials in an insecure manner during connection tests. An attacker who can observe network traffic or trick a user into performing a test action could intercept plaintext passwords for SMB and FTP services, potentially leading to unauthorized access to corporate file shares and sensitive data.

Technical details

An information disclosure vulnerability (CWE-200) exists in the Kyocera Command Center RX web interface on EXOSYS M5521cdn printers. The flaw is located within the Address Book management component, specifically during the 'test' functionality for SMB and FTP configurations. When a user triggers a connection test for a saved entry, the application transmits the associated credentials in plaintext within the network packets. A remote attacker capable of intercepting this traffic or utilizing social engineering to have an authenticated user trigger the test can capture plaintext passwords. The vulnerability is confirmed via a public Proof of Concept (PoC) involving the inspection of outgoing requests from the web panel.

Affected products

  • Kyocera Command Center RX EXOSYS M5521cdn

Timeline

  • 2025-09-18: advisory: NVD publication date
  • 2025-09-19: other: CISA-ADP enrichment and SSVC assessment performed

References