Kyocera's vulnerability footprint spans a moderate product portfolio centered on multifunction office devices and associated firmware, such as the ECOSYS and D-Copia product lines, which are widely embedded across enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, reflecting the complexity of device firmware and embedded web interfaces. The exposure recurs across device models and firmware updates through weakness classes including buffer overflows, path traversal, cross-site scripting, cross-site request forgery, and sensitive information disclosure—attack vectors characteristic of internet-connected peripherals with limited update velocity. Defenders should prioritize inventory and network segmentation of affected multifunction devices, particularly those exposed to untrusted networks, and monitor this vendor's security advisories for firmware updates. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kyocera over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-34260HIGH Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc% | Nov 3, 2023 | 7.5 | 61 | NO | NO |
CVE-2023-34259MEDIUM Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require roo | Nov 3, 2023 | 4.9 | 57 | NO | YES |
CVE-2020-23575HIGH A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary | May 10, 2021 | 7.5 | 54 | NO | YES |
CVE-2022-1026HIGH Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficient | Apr 4, 2022 | 8.6 | 42 | NO | YES |
CVE-2019-13204CRITICAL Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by multiple buffer overflow vulnerabilities in the IPP service. This would allow an unauthenticat | Mar 13, 2020 | 9.8 | 31 | NO | NO |
CVE-2019-13197CRITICAL Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the URI paths of the web application that would allow an un | Mar 13, 2020 | 9.8 | 30 | NO | NO |
CVE-2022-50932HIGH Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file path | Jan 13, 2026 | 7.5 | 29 | NO | NO |
CVE-2019-13202CRITICAL Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the okhtmlfile and failhtmlfile parameters of several funct | Mar 13, 2020 | 9.8 | 29 | NO | NO |
CVE-2019-13201CRITICAL Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the LPD service. This would allow an unauthenticated attack | Mar 13, 2020 | 9.8 | 29 | NO | NO |
CVE-2019-25254HIGH KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can | Dec 24, 2025 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kyocera.
Media articles that mention a CVE ID that affects a product developed by Kyocera — matched by CVE ID, not by vendor name.