Junglewise Threat Intelligence

CVE-2026-39047: Epson L14150 buffer overflow in RAW Printing Service

CVE-2026-39047 · Severity: info · CVSS 9.8 · Published 2026-05-20

Executive brief

A buffer overflow vulnerability exists in the Epson L14150 printer, a multi-function device used in office environments. An attacker can exploit this flaw by sending malicious print data over the network to the device's standard printing port. If successful, this could allow an attacker to crash the printer, disrupt business operations, or potentially gain unauthorized control over the device to access sensitive documents or use it as a foothold in the corporate network.

Technical details

A buffer overflow vulnerability exists in the RAW Printing Service (JetDirect/AppSocket) of the Epson L14150 FL27PB printer. The flaw is located within the embedded printing parser that processes malformed RAW print job payloads received on TCP port 9100. An unauthenticated remote attacker can trigger memory corruption by sending specially crafted network payloads. This can lead to parser instability, firmware crashes (Denial of Service), or potential remote code execution (RCE) within the printer's firmware environment. As of the advisory date, coordinated disclosure is in progress and users should restrict access to port 9100 to trusted network segments.

Affected products

  • Epson L14150 FL27PB

Timeline

  • 2026-05-19: other: Vulnerability discovered by researcher Azhari Ramadhan
  • 2026-05-20: disclosed: Initial public disclosure and CVE assignment

References