CVE-2024-51979
HIGHBrother ADS and DCP Series - Stack-based Buffer Overflow via Malformed Referer Header
Title source: llmDescription
An authenticated attacker may trigger a stack based buffer overflow by performing a malformed request to either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631). The malformed request will contain an empty Origin header value and a malformed Referer header value. The Referer header value will trigger a stack based buffer overflow when the host value in the Referer header is processed and is greater than 64 bytes in length.
References (9)
Core 9
Core References
Various Sources vendor-advisory
https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faq00100846_000
Various Sources vendor-advisory
https://support.brother.com/g/b/link.aspx?prod=group2&faqid=faq00100848_000
Various Sources vendor-advisory
https://support.brother.com/g/b/link.aspx?prod=lmgroup1&faqid=faqp00100620_000
Various Sources vendor-advisory
https://www.fujifilm.com/fbglobal/eng/company/news/notice/2025/0625_announce.html
Various Sources vendor-advisory
https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000007
Vendor Advisory vendor-advisory
https://www.konicaminolta.com/global-en/security/advisory/pdf/km-2025-0001.pdf
Third Party Advisory third-party-advisory
https://www.rapid7.com/blog/post/multiple-brother-devices-multiple-vulnerabilities-fixed
Various Sources technical-description
https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf
Scores
CVSS v3
7.2
EPSS
0.0232
EPSS Percentile
84.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-121
Status
published
Products (50)
Brother Industries, Ltd/ADS-2400N
< T
Brother Industries, Ltd/ADS-2800W
< T
Brother Industries, Ltd/ADS-3000N
< T
Brother Industries, Ltd/ADS-3600W
< T
Brother Industries, Ltd/DCP-7090DW
< M
Brother Industries, Ltd/DCP-7190DN
< V
Brother Industries, Ltd/DCP-7190DW
< M
Brother Industries, Ltd/DCP-7195DW
< R
Brother Industries, Ltd/DCP-9030CDN
< ZE
Brother Industries, Ltd/DCP-B7520DW
< V
... and 40 more
Published
Jun 25, 2025
Tracked Since
Feb 18, 2026