Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Kyocera

First CVE: Feb 19, 2006Active for: 20 yearsTotal CVEs: 31
44.9
VTI Score
High

Kyocera's vulnerability footprint spans a moderate product portfolio centered on multifunction office devices and associated firmware, such as the ECOSYS and D-Copia product lines, which are widely embedded across enterprise environments. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and a moderate tendency toward public exploit availability, reflecting the complexity of device firmware and embedded web interfaces. The exposure recurs across device models and firmware updates through weakness classes including buffer overflows, path traversal, cross-site scripting, cross-site request forgery, and sensitive information disclosure—attack vectors characteristic of internet-connected peripherals with limited update velocity. Defenders should prioritize inventory and network segmentation of affected multifunction devices, particularly those exposed to untrusted networks, and monitor this vendor's security advisories for firmware updates. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
31
Total CVEs
More Total CVEs than 97% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Kyocera over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 19, 2006
20 years ago
Most Recent CVE
Jan 13, 2026
192 days ago

Products(102 total)

Top CVEs

Signals from CVEs in this vendor scope (31 CVEs).

31 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-34260HIGH
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%
Nov 3, 20237.561NONO
CVE-2023-34259MEDIUM
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require roo
Nov 3, 20234.957NOYES
CVE-2020-23575HIGH
A directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacker to retrieve or view arbitrary
May 10, 20217.554NOYES
CVE-2022-1026HIGH
Kyocera multifunction printers running vulnerable versions of Net View unintentionally expose sensitive user information, including usernames and passwords, through an insufficient
Apr 4, 20228.642NOYES
CVE-2019-13204CRITICAL
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by multiple buffer overflow vulnerabilities in the IPP service. This would allow an unauthenticat
Mar 13, 20209.831NONO
CVE-2019-13197CRITICAL
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the URI paths of the web application that would allow an un
Mar 13, 20209.830NONO
CVE-2022-50932HIGH
Kyocera Command Center RX ECOSYS M2035dn contains a directory traversal vulnerability that allows unauthenticated attackers to read sensitive system files by manipulating file path
Jan 13, 20267.529NONO
CVE-2019-13202CRITICAL
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the okhtmlfile and failhtmlfile parameters of several funct
Mar 13, 20209.829NONO
CVE-2019-13201CRITICAL
Some Kyocera printers (such as the ECOSYS M5526cdw 2R7_2000.001.701) were affected by a buffer overflow vulnerability in the LPD service. This would allow an unauthenticated attack
Mar 13, 20209.829NONO
CVE-2019-25254HIGH
KYOCERA Net Admin 3.4.0906 contains a cross-site request forgery vulnerability that allows attackers to create administrative users without proper request validation. Attackers can
Dec 24, 20258.827NONO
View all 31 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products31 CVEs
35%
52%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (3.2%)
Network25 (80.6%)
Unknown3 (9.7%)
Physical0 (0.0%)
Adjacent Network2 (6.5%)
Attack Complexity
Low28 (90.3%)
High0 (0.0%)
Unknown3 (9.7%)
User Interaction
None21 (67.7%)
Unknown3 (9.7%)
Required7 (22.6%)
Privileges Required
Low4 (12.9%)
High3 (9.7%)
None21 (67.7%)
Unknown3 (9.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (31 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
9.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Kyocera.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Kyocera — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Kyocera's Products

View all 4 CNAs →

Top CWEs