CVE-2024-51981 is a medium-severity blind Server-Side Request Forgery (SSRF) vulnerability affecting Brother printers, stemming from a CRLF injection issue that enables HTTP request smuggling. An unauthenticated attacker can exploit this to control HTTP data in an SSRF connection, but cannot receive responses. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating heightened awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Brother Industries, Ltd | ADS-2400N | >= 0, <= TCNA affecteddefault unaffected | |
| Brother Industries, Ltd | ADS-2800W | >= 0, <= TCNA affecteddefault unaffected | |
| Brother Industries, Ltd | ADS-3000N | >= 0, <= TCNA affecteddefault unaffected | |
| Brother Industries, Ltd | ADS-3600W | >= 0, <= TCNA affecteddefault unaffected | |
| Brother Industries, Ltd | DCP-1610W | >= 0, <= ZBCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.