CVE-2024-51978
CRITICAL EXPLOITED NUCLEIBrother/Konica/Toshiba Printers - Default Admin Password Generation
Title source: manualExploitation Summary
CVE-2024-51978 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including iSee857. A Nuclei detection template is also available.
AI-analyzed exploit summary The repository contains functional exploit code for multiple CVEs, including CVE-2024-51978 (BrotherPrinter default password vulnerability). The provided PoC for CVE-2026-22812 demonstrates a command execution vulnerability in OpenCode by creating a session and executing arbitrary commands via a shell endpoint.
Description
An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.
Exploits (1)
The repository contains functional exploit code for multiple CVEs, including CVE-2024-51978 (BrotherPrinter default password vulnerability). The provided PoC for CVE-2026-22812 demonstrates a command execution vulnerability in OpenCode by creating a session and executing arbitrary commands via a shell endpoint.
Nuclei Templates (1)
app="brother-Printer"
References (13)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H