Junglewise Threat Intelligence

CVE-2026-58315: SEIKO EPSON Web Config Cross-Site Request Forgery

CVE-2026-58315 · Severity: medium · CVSS 4.3 · Published 2026-07-07

Executive brief

A security vulnerability exists in the Web Config interface used by various Epson printers and scanners to manage device settings. If an authenticated administrator visits a malicious website while their printer management session is still active, the attacker could remotely change the device's configuration without the user's knowledge. This could lead to unauthorized changes in network settings or device behavior, potentially disrupting business operations.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in the Web Config component of multiple SEIKO EPSON printers and scanners. The vulnerability stems from insufficient validation of requests originating from third-party sites, allowing an attacker to craft a malicious webpage that triggers administrative actions on the device if the victim is currently authenticated to the Web Config interface. Attackers can achieve unauthorized configuration changes. Epson has not released a firmware patch but recommends workarounds including placing devices behind firewalls, using private IP addresses, and ensuring administrators log out immediately after use.

Affected products

  • SEIKO EPSON CORPORATION Web Config Multiple printer and scanner models including EP, EW, PX, SC, and FF series

Timeline

  • 2026-07-07: disclosed: Initial disclosure by JPCERT/CC and Epson
  • 2026-07-07: advisory

References