nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-25356 CVE-2019-25356
MEDIUM
Bematech Printer MP-4200 TH Cross-Site Scripting
Record summary
CVE-2019-25356 has a selected CVSS score of 5.1 (medium); EIP currently links 1 catalogued exploit.
Description
Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printer contains a cross-site scripting vulnerability in the admin configuration page. Attackers can inject malicious scripts via crafted POST requests with malformed 'admin' and 'person' parameters, allowing execution of arbitrary JavaScript in the context of an authenticated user's browser session.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 19, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MP-4200 THBrowse Bematech / MP-4200 TH | CVE List | Version range not supplied | affected |
Proofs of concept
1Catalogued exploits
ExploitDBBematech Printer MP-4200 - Denial of ServiceExploitDB exploitby Jonatas FilNot analyzed1 file
References
5Archived Bematech Homepageproduct
https://web.archive.org/web/20180814065516/https://www.bematech.com.br ExploitDB-47648exploit
https://www.exploit-db.com/exploits/47648 Legacy Hardware Pageproduct
https://www.legacyglobal.com/products/bematech-formerly-logic-controls-mp-4200-thermal-receipt-printer?srsltid=AfmBOor3LXakwJp10bE_8n8YIBKrFPFGFc5DKrxdMGChGQ-Y24i8MVQa VulnCheck Advisory: Bematech Printer MP-4200 TH Cross-Site ScriptingThird-party advisory
https://www.vulncheck.com/advisories/bematech-printer-mp-th-cross-site-scripting