CVE-2025-35970
7.5SEIKO EPSON and FUJIFILM Corporation · Multiple Products (including FRONTIER DX400W)
Multiple printer and imaging products from SEIKO EPSON and FUJIFILM allow unauthorized administrator access due to predictable initial passwords exposed via SNMP.
Executive summary
A critical vulnerability in SEIKO EPSON and FUJIFILM products allows unauthenticated remote attackers to gain administrative access by guessing weak default passwords via SNMP.
Vulnerability
This is a weak credential vulnerability (CWE-1391) where initial administrator passwords can be derived from SNMP information. An unauthenticated remote attacker can leverage this to gain full administrative privileges if the default credentials have not been changed.
Business impact
The ability for an unauthenticated attacker to gain administrative access to networking and imaging equipment presents a severe risk to organizational security. Successful exploitation could lead to full device compromise, unauthorized access to sensitive print jobs or images, and the potential for these devices to be used as a pivot point for lateral movement within the internal network. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent unauthorized administrative control.
Remediation
Immediate Action: Administrators must immediately change the default administrator passwords on all affected SEIKO EPSON and FUJIFILM devices. If the device supports disabling SNMP or restricting SNMP access to trusted management IP addresses, these measures should be implemented immediately.
Proactive Monitoring: Security teams should monitor network traffic for unauthorized SNMP requests originating from outside the management network. Review device access logs for frequent failed login attempts or successful logins from unrecognized IP addresses.
Compensating Controls: Implement network-level access control lists (ACLs) to restrict access to SNMP ports to known, authorized management workstations. Utilizing a firewall to block external access to device management interfaces significantly reduces the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The vulnerability poses a significant risk due to the ease with which an attacker can harvest credentials via SNMP. Organizations should prioritize inventorying all affected SEIKO EPSON and FUJIFILM assets and enforcing a mandatory password rotation policy. Failure to secure these devices may result in unauthorized administrative access, and administrators should consult the provided vendor references for specific guidance on hardening these units.