#VU112341 Missing Authentication for Critical Function in Seiko Epson Corporation products - CVE-2025-4960

 

#VU112341 Missing Authentication for Critical Function in Seiko Epson Corporation products - CVE-2025-4960

Published: July 7, 2025


Vulnerability identifier: #VU112341
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2025-4960
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
EP-10VA
EP-306
EP-30VA
EP-315
EP-50V
EP-707A
EP-710A
EP-711A
EP-712A
EP-713A
EP-714A
EP-715A
EP-716A
EP-717A
EP-806A
EP-807A
EP-808A
EP-810A
EP-811A
EP-812A
EP-813A
EP-814A
EP-815A
EP-816A
EP-817A
EP-879A
EP-880A
EP-881A
EP-882A
EP-883A
EP-884A
EP-885A
EP-886A
EP-887A
EP-979A3
EP-982A3
EP-M476T
EP-M552T
EP-M553T
EW-052A
EW-056A
EW-452A
EW-456A
EW-M5071FT
EW-M530F
EW-M5610FT
EW-M571T
EW-M630T
EW-M634T
EW-M670FT
EW-M674FT
EW-M752T
EW-M754T
EW-M757T
EW-M770T
EW-M873T
EW-M970A3T
EW-M973A3T
LM-C400
LM-C4000
LM-C5000
LM-C6000
LM-M5500
LX-10000F
LX-10010MF
LX-10020M
LX-10050MF
LX-6050MF
LX-7000F
LX-7550MF
PF-71
PF-81
PX-046A
PX-047A
PX-048A
PX-049A
PX-M160T
PX-M161T
PX-M270FT
PX-M270T
PX-M380F
PX-M381FL
PX-M5041F
PX-M5080F
PX-M5081F
PX-M6010F
PX-M6011F
PX-M650F
PX-M6711FT
PX-M6712FT
PX-M680F
PX-M7070FX
PX-M7080FX
PX-M7090FX
PX-M7110F
PX-M7110FP
PX-M7120F
PX-M7120FP
PX-M730F
PX-M780F
PX-M781F
PX-M791FT
PX-M8000FX
PX-M8010FX
PX-M860F
PX-M880FX
PX-M884F
PX-M885F
PX-M886FL
PX-M887F
PX-M890FX
PX-S05
PX-S06
PX-S155
PX-S160T
PX-S161T
PX-S170T
PX-S170UT
PX-S270T
PX-S380
PX-S381L
PX-S5010
PX-S505
PX-S5080
PX-S6010
PX-S6710T
PX-S7070X
PX-S7090X
PX-S7110
PX-S7110P
PX-S7120
PX-S7120P
PX-S730
PX-S740
PX-S8010X
PX-S860
PX-S880X
PX-S884
PX-S885
PX-S887
PX-S890X
SC-PX1V
SC-PX1VL
SC-PX3V
SC-PX5V2
SC-PX7V2
LP-M8170
LP-M8180A
LP-M8180F
LP-S180D
LP-S180DN
LP-S2290
LP-S280DN
LP-S3250
LP-S3290
LP-S3550
LP-S3590
LP-S380DN
LP-S4250
LP-S4290
LP-S6160
LP-S7160
LP-S7180
LP-S8160
LP-S8180
LP-S9070
LP-S950
SC-F100
SC-F1000
SC-F2200
SC-G6000
SC-P20500
SC-P5300
SC-P6500
SC-P6500D
SC-P8500D
SC-P8500DL
SC-P8500DM
SC-S7100
SC-T2100
SC-T3100M
SC-T3100X
SC-T3405
SC-T3700
SC-T3700D
SC-T5100M
SC-T5405
SC-T5700D
SC-T5700DM
SC-T7700D
SC-T7700DL
SC-T7700DM
DS-1630
DS-1730
DS-1760WN
DS-310
DS-32000
DS-360W
DS-40
DS-530
DS-531
DS-560
DS-570W
DS-571W
DS-780N
DS-790WN
DS-870
DS-900WN
DS-970
DS-C420W
DS-C480W
DS-G20000
DS-G30000
ES-50
ES-60W
ES-60WB
ES-60WW
GT-S650
GT-S660
GT-X830
GT-X980
SL-D500
Software vendor:
Seiko Epson Corporation

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to missing authentication for critical function within the helper tool. A remote attacker can trick a victim to execute a specially crafted file and execute arbitrary code on the system.


Remediation

Install updates from vendor's website.

External links