CVE-2021-43716
Received Received - Intake

EPSON EasyMP Network Updater Firmware Update Verification Bypass

Vulnerability report for CVE-2021-43716, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-18

Last updated on: 2026-08-18

Assigner: MITRE

Description

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-18
Last Modified
2026-08-18
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
epson easymp_network_updater 1.20

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2021-43716 is a firmware verification bypass vulnerability in Epson projectors updated via EasyMP Network Updater v1.20. The updater uses a weak CRC32 checksum and reversible encryption instead of cryptographic signatures to validate firmware. Attackers with USB access can bypass checks by recomputing the checksum and re-encrypting malicious firmware, allowing arbitrary code execution on the device.

Detection Guidance

This vulnerability involves a firmware verification bypass in Epson projectors using EasyMP Network Updater v1.20. Detection requires checking for unauthorized firmware modifications or unexpected projector behavior. Inspect USB-connected devices for unknown firmware files or unusual update processes. Monitor network traffic for suspicious projector communication patterns.

Impact Analysis

This vulnerability allows attackers to install malicious firmware on your Epson projector via USB. This could lead to persistent device compromise, denial of service, or turning the projector into a network entry point for further attacks. Physical access to the device is required to exploit it.

Mitigation Strategies

Immediately stop using EasyMP Network Updater v1.20 for firmware updates. Replace the current integrity check with a cryptographic signature verified against a vendor-embedded public key. Ensure all projectors are updated to a patched firmware version if available. Restrict physical USB access to projectors to prevent unauthorized firmware flashing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2021-43716. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart