Get all your news in one place.
100's of premium titles.
One app.
Start reading
Tom’s Hardware
Tom’s Hardware
Technology
Sunny Grimm

689 different Brother printer models all use the serial number to create default password — ridiculous security flaw baked in from manufacturing, can't be fully remediated with firmware

Brother printers join the dark side.

Another reminder to change your devices' default passwords has arrived, thanks to a new critical vulnerability found in Brother printers. 689 different models of Brother printers, plus a handful of other printers from Fujifilm, Toshiba, and Konica Minolta, are susceptible to eight new security vulnerabilities, some of which cannot be patched with firmware updates.

Security company Rapid7 discovered the exploits in a recent investigation of some Brother printers. The most severe of these, CVE-2024-51978, given a 9.8 Critical rating, allows attackers to generate the device's default admin password. The affected models have default passwords created algorithmically using their serial numbers as a seed, so attackers with the printer's serial number (accessible via HTTP thanks to CVE-2024-51977) can create the default password and access the printer and the rest of the network.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.