Executive brief
A vulnerability in several Kyocera TASKalfa printer models allows unauthorized users to access and export the device's internal address book. This address book often contains sensitive information, including usernames and passwords used for network authentication. An attacker could use this information to gain further access to corporate networks or intercept sensitive documents.
Technical details
A vulnerability in the Kyocera Command Center RX web interface allows for unauthorized access to the printer's Address Book feature. The flaw enables an attacker to bypass security measures intended to encrypt incoming data, subsequently allowing for the decryption of stored information. By exploiting this, an attacker can export the entire address book, which includes sensitive plaintext credentials (usernames and passwords) and contact details. The vulnerability affects multiple models in the TASKalfa series. No authentication appears to be required to trigger the export and decryption process.
Affected products
- Kyocera TASKalfa 2552ci
- Kyocera TASKalfa 3252ci
- Kyocera TASKalfa 2553ci
- Kyocera TASKalfa 3253ci
- Kyocera TASKalfa 3554ci
- Kyocera TASKalfa 4052ci
- Kyocera TASKalfa 5052ci
- Kyocera TASKalfa 6052ci
- Kyocera TASKalfa 7052ci
- Kyocera TASKalfa 8052ci
- Kyocera TASKalfa 7353ci
- Kyocera TASKalfa 8353ci
- Kyocera TASKalfa 2554ci
- Kyocera TASKalfa 3254ci
- Kyocera TASKalfa 505
Timeline
- 2026-07-09: disclosed
- 2026-07-09: advisory