Authentication Bypass Vulnerability in EPSON WebConfig and Web Control Products
CVE-2025-64310

9.3CRITICAL

What is CVE-2025-64310?

EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products exhibit a critical flaw by not adequately restricting authentication attempts. This issue can be exploited through brute force attacks, potentially allowing an attacker to discover an administrative user's password. The vulnerability poses a significant risk, as unauthorized access can lead to further compromise of the product's functionality and security.

Affected Version(s)

Epson Web Control for SEIKO EPSON Projector Products see the information provided by the vendor

EPSON WebConfig for SEIKO EPSON Projector Products see the information provided by the vendor

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.