An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://epson.com/Support/wa00826 | |
https://seclists.org/fulldisclosure/2024/Jul/14 | mailing list |