CVE-2017-16249 describes a remotely exploitable Denial of Service (DoS) vulnerability in the Debut embedded HTTP server, specifically affecting Brother DCP-J132W printers and their firmware. A single malformed HTTP POST request can cause the server to hang for an extended period, blocking network print jobs and web interface access. This vulnerability has a CVSS score of 7.5 (HIGH) due to its network-based attack vector, low complexity, and high impact on availability. While not listed in CISA's KEV catalog, public exploit modules exist in Metasploit and ExploitDB, and it has garnered significant community discussion and media coverage, indicating awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.20CPE matchmatch criteria | cpe:2.3:o:brother:dcp-j132w_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.