An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.
References
Configurations
No configuration.
History
15 Apr 2026, 00:35
| Type | Values Removed | Values Added |
|---|---|---|
| Summary | (es) Se descubrió un problema en dispositivos Epson Expression Home XP255 20.08.FM10I8. Por defecto, el dispositivo viene (y funciona) sin contraseña. En ningún momento se le solicita al usuario configurar una contraseña en el dispositivo (dejando un número de dispositivos sin contraseña). En este caso, cualquiera que se conecte al panel de administración web es capaz de convertirse en administrador sin usar ninguna credencial. |
04 Nov 2025, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
08 Nov 2024, 17:35
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-276 | |
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
07 Nov 2024, 18:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-11-07 18:15
Updated : 2026-04-15 00:35
NVD link : CVE-2019-20458
Mitre link : CVE-2019-20458
CVE.ORG link : CVE-2019-20458
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions
