Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Epson

First CVE: Dec 8, 2010Active for: 16 yearsTotal CVEs: 31
36.4
VTI Score
Medium

Epson's vulnerability profile spans a large portfolio of office equipment, printers, and peripherals, though the volume of disclosures remains modest relative to the device footprint in deployment. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, concentrating in widely deployed multifunction devices such as the WorkForce series and associated firmware, as well as enterprise server components like the TSE Server. The exposure recurs through web-interface and authentication-oriented weakness classes including cross-site scripting, missing authentication for critical functions, cross-site request forgery, and improper authentication, reflecting the embedded web-service attack surface of networked office equipment. Defenders should prioritize firmware updates for internet-accessible or network-adjacent devices and restrict administrative access to web interfaces; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Epson over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 8, 2010
15 years ago
Most Recent CVE
Mar 5, 2026
141 days ago

Products(516 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-5550MEDIUM
Versions of Epson AirPrint released prior to January 19, 2018 contain a reflective cross-site scripting (XSS) vulnerability, which can allow untrusted users on the network to hijac
Feb 8, 20186.139NONO
CVE-2017-12861CRITICAL
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-scree
Oct 10, 20179.833NONO
CVE-2017-12860CRITICAL
The Epson "EasyMP" software is designed to remotely stream a users computer to supporting projectors.These devices are authenticated using a unique 4-digit code, displayed on-scree
Oct 10, 20179.832NONO
CVE-2017-6443MEDIUM
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.
Mar 15, 20176.132NOYES
CVE-2026-23767CRITICAL
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict s
Mar 5, 20269.831NONO
CVE-2020-6091CRITICAL
An exploitable authentication bypass vulnerability exists in the ESPON Web Control functionality of Epson EB-1470Ui MAIN: 98009273ESWWV107 MAIN2: 8X7325WWV303. A specially crafted
May 22, 20209.130NONO
CVE-2022-36133CRITICAL
The WebConfig functionality of Epson TM-C3500 and TM-C7500 devices with firmware version WAM31500 allows authentication bypass.
Nov 25, 20229.129NONO
CVE-2020-28929CRITICAL
Unrestricted access to the log downloader functionality in EPSON EPS TSE Server 8 (21.0.11) allows an unauthenticated attacker to remotely retrieve administrative hashed credential
Dec 16, 20209.828NONO
CVE-2020-12695HIGH
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment th
Jun 8, 20207.528NONO
CVE-2018-19248CRITICAL
The web service on Epson WorkForce WF-2861 10.48 LQ22I3(Recovery-mode), WF-2861 10.51.LQ20I6, and WF-2861 10.52.LQ17IA devices allows remote attackers to upload a firmware file and
Dec 24, 20189.128NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
39%
39%
23%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (12.9%)
Network25 (80.6%)
Unknown2 (6.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (87.1%)
High2 (6.5%)
Unknown2 (6.5%)
User Interaction
None18 (58.1%)
Unknown2 (6.5%)
Required11 (35.5%)
Privileges Required
Low3 (9.7%)
High1 (3.2%)
None25 (80.6%)
Unknown2 (6.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.2% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Epson.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Epson — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Epson's Products

View all 5 CNAs →

Top CWEs