Vulnerabilities in Printer and Scanner Web Config (CSRF)

Vulnerability Reference: CVE-2026-58315

 
Description:
We have identified a vulnerability in Web Config (*1) that allows users to check device status and change settings via a web browser on certain printer and scanner products.
(*1) Web Config is a feature that allows users to check the device status and change settings by entering the device's IP address into the URL field of a web browser such as Edge or Safari.
 
Identified Vulnerability
This is a Cross-Site Request Forgery (CSRF) vulnerability.
If a user accesses a malicious website created by a third party, there is a possibility that the settings of the affected device may be altered via the Web Config interface.
  
Impact:
Currently, there have been no reports of attacks exploiting this vulnerability.
  
Affected Models
L5590L4260L3150
L3556L4266L5190
L3550L4261M1120
L8050L5290M3170
L18050L5296M2170
L11050L3250M1170
M2050L3256L4150
M1050L3251L4160
XP-4101L1250L6160
XP-2101L1256L6170
WF-2851L1251L6190
L14150L6490WF-2861
L6290L6460WF-100
L6270SC-F130 
L6260L3156 
Workaround
  • Do not connect directly to the internet and install the product within a network protected by a firewall.
  • Please log out after logging in as an administrator. Do not stay logged in as an administrator in Web Config for long periods and always log out once the work is complete.
  • While logged in as an administrator, please do not browse suspicious websites, click on unreliable links, or manipulate unknown files.