CVE-2026-23767

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
05/03/2026
Last modified:
09/03/2026

Description

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:epson:sb-h50_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:sb-h50:-:*:*:*:*:*:*:*
cpe:2.3:o:epson:tm-h6000v_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:tm-h6000v:-:*:*:*:*:*:*:*
cpe:2.3:o:epson:tm-l100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:tm-l100:-:*:*:*:*:*:*:*
cpe:2.3:o:epson:tm-m10_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:tm-m10:-:*:*:*:*:*:*:*
cpe:2.3:o:epson:tm-m30_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:tm-m30:-:*:*:*:*:*:*:*
cpe:2.3:o:epson:tm-m30ii_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:tm-m30ii:-:*:*:*:*:*:*:*
cpe:2.3:o:epson:tm-m30ii-h_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:epson:tm-m30ii-h:-:*:*:*:*:*:*:*
cpe:2.3:o:epson:tm-m30ii-s_firmware:-:*:*:*:*:*:*:*