Multi-Function Printers Vulnerable to Serial Number Discovery via eSCL Protocol by Brother
CVE-2025-8452
Key Information:
- Vendor
Brother Industries, Ltd
- Vendor
- CVE Published:
- 12 August 2025
Badges
What is CVE-2025-8452?
A vulnerability exists in Brother multi-function printers that utilize the eSCL protocol, allowing attackers on the local network to discover the serial number of these devices. This serial number can be exploited in conjunction with a related vulnerability to calculate the default administrator password, compromising device security. To mitigate this risk, it is essential to change the default administrator password, as this would prevent the calculated password from being effective.
Affected Version(s)
ADS-1350W 0
ADS-1800W 0
ADS-2700We 0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
