CVE-2019-25401 describes a denial-of-service vulnerability in the admin configuration page of Bematech (formerly Logic Controls, now Elgin) MP-4200 TH printers. Remote attackers can crash the printer's web service by sending crafted POST requests with malformed 'admin' and 'person' parameters. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a high severity due to its network-based attack vector, low attack complexity, and complete denial-of-service impact. There is currently no evidence of active exploitation, and no public exploit code or Metasploit modules are available. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Bematech | MP-4200 | MP-4200 THCNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.