CVE-2026-73542
Deferred Deferred - Pending Action

SEIKO EPSON Printers and Scanners Revoked Root Certificates MITM Vulnerability

Vulnerability report for CVE-2026-73542, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-28

Assigner: JPCERT/CC

Description

Multiple SEIKO EPSON printers and scanners contain revoked root certificates. A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product. As for the details of the affected products and versions, refer to the vendor's information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-28
Generated
2026-09-09
AI Q&A
2026-08-20
EPSS Evaluated
2026-09-07
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
seiko_epson printers *
seiko_epson scanners *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-296 The product does not follow, or incorrectly follows, the chain of trust for a certificate back to a trusted root certificate, resulting in incorrect trust of any resource that is associated with that certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Multiple SEIKO EPSON printers and scanners contain revoked root certificates. This allows a man-in-the-middle attacker to intercept and potentially decrypt communication data transmitted by the affected devices.

Detection Guidance

This vulnerability involves revoked root certificates in Epson printers and scanners. Detection requires checking installed certificates on affected devices. Use the Web Config tool provided by Epson to inspect and compare certificates against the latest trusted versions. No direct command-line detection is specified in the provided resources.

Impact Analysis

An attacker could intercept sensitive data transmitted by the printer or scanner, such as documents or network traffic. This may lead to unauthorized access to confidential information if the intercepted data is not encrypted.

Compliance Impact

This vulnerability could lead to unauthorized access to personal or sensitive data, potentially violating GDPR or HIPAA requirements for data protection and confidentiality. Organizations must address this to maintain compliance.

Mitigation Strategies

Update the root certificates in affected Epson printers and scanners using the developer's instructions or the Web Config tool provided by Epson. Remove old or revoked certificates and install the new ones to prevent man-in-the-middle attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73542. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart