Cross-site scripting (XSS) vulnerability on Brother Printers and All-in One Machines

Vulnerability Reference: CVE-2018-11581
Release Date:July 1st, 2018
Impact:CVSS v3 4.8 Medium

 

Description

 

Cross-site scripting (XSS) vulnerability on some Brother Printers and All-in One Machines can allow remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.

 

Solution

 

Please check Firmware Update status. If you are using any of these products, please update the machine to the latest firmware or read the workaround below.

 

Workaround

 

Please use the product on a network protected by a firewall or other protective system. If you do not use Web Based Management, you can prevent attack by disabling Web Based Management on the machine.

 

Firmware Update status

 

Please see Firmware Update status.

 

Firmware Update Tool

 

Please download Firmware Update Tool.

 

 

你已經查看過使用說明書了嗎?

如果您需要進一步的協助, 請聯絡Brother客戶服務:

內容意見回饋

請於下方回饋您的意見以幫助我們提升服務的品質

步驟一: 此頁面的資訊對您有幫助嗎

步驟二: 你有任何其他想要提出的意見嗎?

請注意, 此表格僅用做意見回饋使用