Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Brother

First CVE: Oct 4, 2002Active for: 24 yearsTotal CVEs: 23
38.4
VTI Score
Medium

Brother manufactures a broadly deployed portfolio of multifunction printers and document imaging devices across enterprise and small-business settings, creating a distributed attack surface spanning firmware, web interfaces, and embedded networking components. Vulnerabilities affecting the vendor reach serious severity with a meaningful tendency toward critical outcomes, and frequently acquire public exploit code. The recurring exposure centers on flagship multifunction models such as the MFC-9970CDW and HL-L2380DW series and clusters around cross-site scripting in web interfaces, exposure of sensitive device information, and out-of-bounds write conditions in firmware, reflecting the web-enabled and firmware-intensive nature of networked printing devices. Defenders should track this vendor's firmware releases and prioritize patching for internet-reachable or administratively accessible printer interfaces, as these devices often remain active for extended periods with minimal monitoring; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
23
Total CVEs
More Total CVEs than 96% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Brother over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2002
23 years ago
Most Recent CVE
Jan 16, 2026
189 days ago

Products(774 total)

Top CVEs

Signals from CVEs in this vendor scope (23 CVEs).

23 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-16249HIGH
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (
Nov 10, 20177.575NOYES
CVE-2017-7588CRITICAL
On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC
Apr 12, 20179.860NOYES
CVE-2019-13192CRITICAL
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would al
Mar 13, 20209.830NONO
CVE-2017-2244HIGH
Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vec
Jul 7, 20178.828NONO
CVE-2019-13193HIGH
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would a
Mar 13, 20208.827NONO
CVE-2020-36929HIGH
Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary cod
Jan 16, 20267.825NONO
CVE-2020-36928HIGH
Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in
Jan 16, 20267.825NONO
CVE-2018-11581MEDIUM
Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.
Jun 1, 20184.825NOYES
CVE-2017-12568HIGH
Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows remote attackers to hang the printer (disrupting its networ
Aug 6, 20177.524NONO
CVE-2019-13194HIGH
Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated us
Mar 13, 20207.523NONO
View all 23 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products23 CVEs
39%
48%
9%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (17.4%)
Network13 (56.5%)
Unknown5 (21.7%)
Physical1 (4.3%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (78.3%)
High0 (0.0%)
Unknown5 (21.7%)
User Interaction
None14 (60.9%)
Unknown5 (21.7%)
Required4 (17.4%)
Privileges Required
Low4 (17.4%)
High1 (4.3%)
None13 (56.5%)
Unknown5 (21.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (23 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
1 CVE
4.3% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.0% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Brother.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Brother — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Brother's Products

View all 3 CNAs →

Top CWEs