An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sat, 26 Jul 2025 01:30:00 +0900


Wed, 16 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.7188}

epss

{'score': 0.46351}


Fri, 27 Jun 2025 23:30:00 +0900


Wed, 25 Jun 2025 23:15:00 +0900

Type Values Removed Values Added
Title Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, and Toshiba Tec. Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
References

Wed, 25 Jun 2025 22:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 25 Jun 2025 16:30:00 +0900

Type Values Removed Values Added
Description An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Title Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, and Toshiba Tec.
Weaknesses CWE-1391
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2025-07-25T16:19:55.848Z

Reserved: 2024-11-04T17:19:18.808Z

Link: CVE-2024-51978

cve-icon Vulnrichment

Updated: 2025-06-27T13:51:00.720Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-25T08:15:31.223

Modified: 2025-07-25T17:15:30.143

Link: CVE-2024-51978

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses