CVE-2024-51982
published 2025-06-25CVE-2024-51982: An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
7.13%
93.5th percentile
An unauthenticated attacker who can connect to TCP port 9100 can issue a Printer Job Language (PJL) command that will crash the target device. The device will reboot, after which the attacker can reissue the command to repeatedly crash the device. A malformed PJL variable FORMLINES is set to a non number value causing the target to crash.
Affected
216 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| brother_industries_ltd | ads-2400n | A – T | — |
| brother_industries_ltd | ads-2800w | A – T | — |
| brother_industries_ltd | ads-3000n | A – T | — |
| brother_industries_ltd | ads-3600w | A – T | — |
| brother_industries_ltd | dcp-7090dw | <= M | — |
| brother_industries_ltd | dcp-7190dn | <= V | — |
| brother_industries_ltd | dcp-7190dw | <= M | — |
| brother_industries_ltd | dcp-7195dw | <= R | — |
| brother_industries_ltd | dcp-9030cdn | <= ZE | — |
| brother_industries_ltd | dcp-b7520dw | <= V | — |
| brother_industries_ltd | dcp-b7520dw | A – V | — |
| brother_industries_ltd | dcp-b7530dn | <= V | — |
| brother_industries_ltd | dcp-b7535dw | <= V | — |
| brother_industries_ltd | dcp-b7535dw | A – V | — |
| brother_industries_ltd | dcp-c421w | <= 1.04(D) | — |
| brother_industries_ltd | dcp-j1100dw | <= P | — |
| brother_industries_ltd | dcp-j572dw | <= P | — |
| brother_industries_ltd | dcp-j572n | <= W | — |
| brother_industries_ltd | dcp-j577n | <= W | — |
| brother_industries_ltd | dcp-j582n | <= W | — |
| brother_industries_ltd | dcp-j587n | A – F | — |
| brother_industries_ltd | dcp-j772dw | <= T | — |
| brother_industries_ltd | dcp-j774dw | <= T | — |
| brother_industries_ltd | dcp-j972n | <= Y | — |
| brother_industries_ltd | dcp-j973n-w_b | <= Y | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdfhttps://github.com/sfewer-r7/BrotherVulnerabilitieshttps://support.brother.com/g/b/link.aspx?prod=group2&faqid=faq00100846_000https://www.fujifilm.com/fbglobal/eng/company/news/notice/2025/0625_announce.htmlhttps://www.rapid7.com/blog/post/multiple-brother-devices-multiple-vulnerabilities-fixedhttps://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000007https://assets.contentstack.io/v3/assets/blte4f029e766e6b253/blt6495b3c6adf2867f/685aa980a26c5e2b1026969c/vulnerability-disclosure-whitepaper.pdf
2025-06-25
Published