Easily Guessable Initial Administrator Password Vulnerability in SEIKO EPSON and FUJIFILM Products
CVE-2025-35970

8.7HIGH

Key Information:

Vendor
CVE Published:
7 August 2025

What is CVE-2025-35970?

Multiple products from SEIKO EPSON and FUJIFILM Corporation exhibit a vulnerability where the initial administrator password is publicly accessible and easily guessable via SNMP (Simple Network Management Protocol). If users neglect to change the default password, a remote attacker with SNMP access can potentially gain unauthorized administrator privileges, leading to significant security risks. Organizations utilizing these products are strongly advised to modify the initial password to mitigate this vulnerability.

Affected Version(s)

FRONTIER DX400W all versions

Multiple EPSON product see the information provided by the vendor

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-35970 : Easily Guessable Initial Administrator Password Vulnerability in SEIKO EPSON and FUJIFILM Products