More than 740 printer models (689 from Brother and 53 from other manufacturers such as Fujifilm, Toshiba and Konica Minolta)have a serious security flaw: default administrator passwords that can be predicted and exploited by remote attackers. Most worryingly? The problem cannot be fixed by updating the firmware on existing devices.

The vulnerability has been recorded as CVE-2024-51978 and is part of a larger set of eight vulnerabilities identified by researchers Rapid7after extensive research into Brother devices.
| CVE | Description | Affected Service | CVSS |
|---|---|---|---|
| CVE-2024-51977 | An unauthorized attacker can leak sensitive information | HTTP (Port 80), HTTPS (Port 443), IPP (Port 631) | 5.3 |
| CVE-2024-51978 | An unauthorized attacker can create the device's default administrator password | HTTP (Port 80), HTTPS (Port 443), IPP (Port 631) | 9.8 |
| CVE-2024-51979 | An authorized attacker can trigger a stack based buffer overflow | HTTP (Port 80), HTTPS (Port 443), IPP (Port 631) | 7.2 |
| CVE-2024-51980 | An unauthorized attacker can force the device to open a TCP connection | Web Services over HTTP (Port 80) | 5.3 |
| CVE-2024-51981 | An unauthorized attacker can force the device to execute an arbitrary HTTP request | Web Services over HTTP (Port 80) | 5.3 |
| CVE-2024-51982 | An unauthorized attacker can cause the device to stop working | PJL (Port 9100) | 7.5 |
| CVE-2024-51983 | An unauthorized attacker can cause the device to stop working | Web Services over HTTP (Port 80) | 7.5 |
| CVE-2024-51984 | An authorized attacker can reveal the password of a configured external service | LDAP, FTP | 6.8 |
The security hole is extremely dangerous, as it can be exploited in combination with other vulnerabilities to find the administrator password, take control of the device, execute arbitrary code, and even interfere with the network to which the devices are connected.
See also: IBM i vulnerability allows privilege escalation
Not all of the defects affect all Brother printer models, but 46 Fujifilm, 6 Konica Minolta, 5 Ricoh , and 2 Toshiba models.
The danger behind the default password
The heart of the problem lies in the way the default passwords are generated. These are generated at the factory when the printers are manufactured, using an algorithm based on the serial number of each device. Although seemingly secure, the algorithm is in practice easily reversible.
According to Rapid7's technical analysis, the code generation process follows these steps:
- Get the first 16 characters of the serial number.
- Add 8 bytes from a static “salt” table.
- Hash using the SHA256 algorithm.
- Encoding the Hash with Base64.
- Selecting the first 8 characters and replacing some letters with special characters.
How attackers gain access to Brother printers
Attackers can leak the serial number of the target printer using various methods or by exploiting CVE-2024-51977. From there, they apply the now-known algorithm to generate the default administrator password and gain access to the device's configuration environment as an administrator
See also: CISA added three new vulnerabilities to the KEV List
Once the attacker logs in as an administrator, the exploitation possibilities are extensive:
- Resetting the device
- Access saved scans and address books
- Exploiting CVE-2024-51979 for remote code execution
- Using CVE-2024-51984 to collect credentials
Apocalyptic research and its… limits
Rapid7 began the responsible disclosure process in May 2024 , with the assistance of JPCERT /CC , to coordinate updates from other manufacturers. While most vendors—including Brother, Fujifilm, Konica Minolta, Ricoh, and Toshiba—have issued firmware fixes , CVE -2024-51978 remains a special case.

This vulnerability stems from the way devices are manufactured and default passwords. Therefore, all devices manufactured before the issue was discovered are considered vulnerable unless users have manually changed the administrator password.
As Rapid7 points out, Brother has acknowledged that the vulnerability cannot be fully addressed through a firmware update, as it requires modification of the manufacturing process itself.
What users can do
For owners of vulnerable Brother printer models, it is imperative to immediately change the default admin password . Immediately after, the latest available software updates should be applied .
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Citrix: NetScaler vulnerability used for DoS attacks
Additionally, it is recommended to restrict access to the printer's admin interfaces via insecure protocols and external networks. Finally, manufacturers have already published detailed security bulletins, with instructions and countermeasures, available for affected models from Brother, Konica Minolta, Fujifilm, Ricoh and Toshiba.
The situation described is serious and revealing of the long-standing security problems associated with devices IoT and printers, which are often neglected from a security perspective by both manufacturers and users.
Printers, scanners, and other connected devices are often not treated as potentially dangerous entry points, when in fact they are easily accessible and with inadequate authentication.
Requiring the average user to change their password and understand the technical details themselves is insufficient. Most users don’t even know about it or don’t have the skills to do it properly. Security should be “by design” and not an afterthought
Source: www.bleepingcomputer.com
