ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.
History

Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Epson
Epson esc Pos
Vendors & Products Epson
Epson esc Pos

Fri, 06 Mar 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 06:00:00 +0000

Type Values Removed Values Added
Description ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.
Weaknesses CWE-306
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published: 2026-03-05T05:34:40.895Z

Updated: 2026-03-06T10:21:28.591Z

Reserved: 2026-01-16T02:20:20.477Z

Link: CVE-2026-23767

cve-icon Vulnrichment

Updated: 2026-03-06T10:21:23.132Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-05T06:16:22.227

Modified: 2026-03-06T11:16:08.797

Link: CVE-2026-23767

cve-icon Redhat

No data.