常见问题解答与故障排除

常见问题解答与故障排除

Cross-site scripting (XSS) vulnerability on Brother Printers and All-in One Machines

Vulnerability Reference: CVE-2018-11581
Release Date:July 1st, 2018
Impact:CVSS v3 4.8 Medium

 

Description

 

Cross-site scripting (XSS) vulnerability on some Brother Printers and All-in One Machines can allow remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.

 

Solution

 

Please check Firmware Update status. If you are using any of these products, please update the machine to the latest firmware or read the workaround below.

 

Workaround

 

Please use the product on a network protected by a firewall or other protective system. If you do not use Web Based Management, you can prevent attack by disabling Web Based Management on the machine.

 

Firmware Update status

 

Please see Firmware Update status.

 

Firmware Update Tool

 

Please download Firmware Update Tool.

 

 

您的问题未被解答时,是否查看过其它常见问题解答?

是否查看过说明书?

如果需要更多的帮助,请联系 Brother 客户服务中心:

内容反馈

请在下方提供您的反馈,帮助我们改进支持服务。

步骤 1:本页上的信息对您有帮助吗?

步骤 2:您是否有其它意见需要添加?

请注意本表格仅用于提供反馈。