Kyocera
kyocera
31 CVEs • 100 products
Products (100)
Click to collapseToggle
Products (100)
Click to collapse
CVEs (31)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file paths under the /js/ path. Attackers can exp...Show more |
KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can craft malicious web pages that automati...Show more |
KYOCERA Net Admin 3.4.0906 contains an XML External Entity (XXE) injection vulnerability in the Multi-Set Template Editor that allows unauthenticated attackers to read arbitrary system files. Attackers can craft a malici...Show more |
Kyocera Device Manager before 3.1.1213.0 allows NTLM credential exposure during UNC path authentication via a crafted change from a local path to a UNC path. It allows administrators to configure the backup location of t...Show more |
1Kyocera 1D Copia253mf Plus Firmware Nov 21, 2024 Nov 3, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a "nicht einloggen" error rather than a falsch error. |
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc dire...Show more |
1Kyocera 1D Copia253mf Plus Firmware Nov 21, 2024 Nov 3, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists be...Show more |
3Kyocera OlivettiTriumph Adler3Mobile Print Mobile PrintMobile PrintFeb 7, 2025 Apr 13, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 KYOCERA Mobile Print' v3.2.0.230119 and earlier, 'UTAX/TA MobilePrint' v3.2.0.230119 and earlier, and 'Olivetti Mobile Print' v3.2.0.230119 and earlier are vulnerable to improper intent handling. When a malicious app is...Show more |
1Kyocera 38Ecosys M2535dn Firmware Ecosys M6526cdn FirmwareEcosys M6526cidn Firmware+35 moreApr 24, 2025 Dec 5, 2022 N/A· v4 4.8 MEDIUM· v3 N/A· v2 Stored cross-site scripting vulnerability in Kyocera Document Solutions MFPs and printers allows a remote authenticated attacker with an administrative privilege to inject arbitrary script. Affected products/versions are...Show more |
1Kyocera 38Ecosys M2535dn Firmware Ecosys M6526cdn FirmwareEcosys M6526cidn Firmware+35 moreApr 24, 2025 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the product settings without authentication by sending a specially crafted...Show more |
1Kyocera 38Ecosys M2535dn Firmware Ecosys M6526cdn FirmwareEcosys M6526cidn Firmware+35 moreApr 24, 2025 Dec 5, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session info...Show more |
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficiently protected address book export functio...Show more |
1Kyocera 1D Copia253mf Plus Firmware Nov 21, 2024 May 10, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary files from the affected server. |
1Kyocera 1Ecosys M2640idw Firmware Nov 21, 2024 Nov 17, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addition a new contact in "Machine Address Book". Successful exploitation of this vulnerability can lead...Show more |
1Kyocera 1Ecosys M5526cdw Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the okhtmlfile and failhtmlfile parameters of several functionalities of the web application that w...Show more |
1Kyocera 1Ecosys M5526cdw Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the LPD service. This would allow an unauthenticated attacker to cause a Denial of Service (DoS) in...Show more |
1Kyocera 1Ecosys M5526cdw Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Reflected XSS. Successful exploitation of this vulnerability can lead to session hijacking of the administrat...Show more |
1Kyocera 1Ecosys M5526cdw Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) did not implement any mechanism to avoid CSRF. Successful exploitation of this vulnerability can lead to the takeover of a local account on the device. |
1Kyocera 1Ecosys M5526cdw Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web application of several Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) was affected by Stored XSS. Successful exploitation of this vulnerability can lead to session hijacking of the administrator...Show more |
1Kyocera 1Ecosys M5526cdw Firmware Nov 21, 2024 Mar 13, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the URI paths of the web application that would allow an unauthenticated attacker to perform a Deni...Show more |