Cross-site scripting (XSS) vulnerability on Brother Printers and All-in One Machines

Vulnerability Reference: CVE-2018-11581
Release Date:July 1st, 2018
Impact:CVSS v3 4.8 Medium

 

Description

 

Cross-site scripting (XSS) vulnerability on some Brother Printers and All-in One Machines can allow remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.

 

Solution

 

Please check Firmware Update status. If you are using any of these products, please update the machine to the latest firmware or read the workaround below.

 

Workaround

 

Please use the product on a network protected by a firewall or other protective system. If you do not use Web Based Management, you can prevent attack by disabling Web Based Management on the machine.

 

Firmware Update status

 

Please see Firmware Update status.

 

Firmware Update Tool

 

Please download Firmware Update Tool.

 

 

질문의 대답이 없는 경우 다른 FAQ를 확인했습니까?

설명서를 확인했습니까?

도움이 더 필요한 경우 Brother 고객 서비스에 문의하십시오.

내용 피드백

지원을 개선하는 데 도움이 되도록 아래에 피드백을 제공하십시오.

1단계: 이 페이지의 정보가 얼마나 도움이 됩니까?

2단계: 추가할 의견이 있습니까?

이 양식은 피드백용으로만 사용됩니다.