Brother manufactures a broadly deployed portfolio of multifunction printers and document imaging devices across enterprise and small-business settings, creating a distributed attack surface spanning firmware, web interfaces, and embedded networking components. Vulnerabilities affecting the vendor reach serious severity with a meaningful tendency toward critical outcomes, and frequently acquire public exploit code. The recurring exposure centers on flagship multifunction models such as the MFC-9970CDW and HL-L2380DW series and clusters around cross-site scripting in web interfaces, exposure of sensitive device information, and out-of-bounds write conditions in firmware, reflecting the web-enabled and firmware-intensive nature of networked printing devices. Defenders should track this vendor's firmware releases and prioritize patching for internet-reachable or administratively accessible printer interfaces, as these devices often remain active for extended periods with minimal monitoring; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Brother over time
Signals from CVEs in this vendor scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16249HIGH The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying ( | Nov 10, 2017 | 7.5 | 75 | NO | YES |
CVE-2017-7588CRITICAL On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC | Apr 12, 2017 | 9.8 | 60 | NO | YES |
CVE-2019-13192CRITICAL Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a heap buffer overflow vulnerability as the IPP service did not parse attribute names properly. This would al | Mar 13, 2020 | 9.8 | 30 | NO | NO |
CVE-2017-2244HIGH Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vec | Jul 7, 2017 | 8.8 | 28 | NO | NO |
CVE-2019-13193HIGH Some Brother printers (such as the HL-L8360CDW v1.20) were affected by a stack buffer overflow vulnerability as the web server did not parse the cookie value properly. This would a | Mar 13, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-36929HIGH Brother BRPrint Auditor 3.0.7 contains an unquoted service path vulnerability in its Windows service configurations that allows local attackers to potentially execute arbitrary cod | Jan 16, 2026 | 7.8 | 25 | NO | NO |
CVE-2020-36928HIGH Brother BRAgent 1.38 contains an unquoted service path vulnerability in the WBA_Agent_Client service running with LocalSystem privileges. Attackers can exploit the unquoted path in | Jan 16, 2026 | 7.8 | 25 | NO | NO |
CVE-2018-11581MEDIUM Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html. | Jun 1, 2018 | 4.8 | 25 | NO | YES |
CVE-2017-12568HIGH Denial of Service vulnerability in Debut embedded httpd 1.20 in Brother DCP-J132W (and probably other DCP models) allows remote attackers to hang the printer (disrupting its networ | Aug 6, 2017 | 7.5 | 24 | NO | NO |
CVE-2019-13194HIGH Some Brother printers (such as the HL-L8360CDW v1.20) were affected by different information disclosure vulnerabilities that provided sensitive information to an unauthenticated us | Mar 13, 2020 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (23 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Brother.
Media articles that mention a CVE ID that affects a product developed by Brother — matched by CVE ID, not by vendor name.