Vulnerability Reference: CVE-2026-58315
Description:
We have identified a vulnerability in Web Config (*1) that allows users to check device status and change settings via a web browser on certain printer and scanner products.
(*1) Web Config is a feature that allows users to check the device status and change settings by entering the device's IP address into the URL field of a web browser such as Edge or Safari.
(*1) Web Config is a feature that allows users to check the device status and change settings by entering the device's IP address into the URL field of a web browser such as Edge or Safari.
Identified Vulnerability
This is a Cross-Site Request Forgery (CSRF) vulnerability.
If a user accesses a malicious website created by a third party, there is a possibility that the settings of the affected device may be altered via the Web Config interface.
If a user accesses a malicious website created by a third party, there is a possibility that the settings of the affected device may be altered via the Web Config interface.
Impact:
Currently, there have been no reports of attacks exploiting this vulnerability.
Affected Models
| L5590 | L4260 | L3150 |
| L3556 | L4266 | L5190 |
| L3550 | L4261 | M1120 |
| L8050 | L5290 | M3170 |
| L18050 | L5296 | M2170 |
| L11050 | L3250 | M1170 |
| M2050 | L3256 | L4150 |
| M1050 | L3251 | L4160 |
| XP-4101 | L1250 | L6160 |
| XP-2101 | L1256 | L6170 |
| WF-2851 | L1251 | L6190 |
| L14150 | L6490 | WF-2861 |
| L6290 | L6460 | WF-100 |
| L6270 | SC-F130 | |
| L6260 | L3156 |
Workaround
- Do not connect directly to the internet and install the product within a network protected by a firewall.
- Please log out after logging in as an administrator. Do not stay logged in as an administrator in Web Config for long periods and always log out once the work is complete.
- While logged in as an administrator, please do not browse suspicious websites, click on unreliable links, or manipulate unknown files.