An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Jun 2025 14:30:00 +0000
Wed, 25 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, and Toshiba Tec. | Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc. |
References |
|
Wed, 25 Jun 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 25 Jun 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request. | |
Title | Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, and Toshiba Tec. | |
Weaknesses | CWE-1391 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: rapid7
Published: 2025-06-25T07:17:32.423Z
Updated: 2025-06-27T13:51:00.720Z
Reserved: 2024-11-04T17:19:18.808Z
Link: CVE-2024-51978

Updated: 2025-06-27T13:51:00.720Z

Status : Awaiting Analysis
Published: 2025-06-25T08:15:31.223
Modified: 2025-06-27T14:15:32.593
Link: CVE-2024-51978

No data.