Back to overview

CVE-2025-64310

CRITICAL
9.8
CVSS 3.1
Description
EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack.

Metadata

CVE ID
CVE-2025-64310
State
PUBLISHED
Assigner
jpcert
Reserved
2025-10-30 00:25 UTC
Published
2025-11-21 02:36 UTC
Last updated
2025-12-23 02:28 UTC
Primary CWE
CWE-307
Improper restriction of excessive authentication attempts
Vendor / Product
SEIKO EPSON CORPORATION / EPSON WebConfig for SEIKO EPSON Projector Products
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (2)
VendorProductPlatformVersions
SEIKO EPSON CORPORATION Epson Web Control for SEIKO EPSON Projector Products see the information provided by the vendor
SEIKO EPSON CORPORATION EPSON WebConfig for SEIKO EPSON Projector Products see the information provided by the vendor
Weakness (CWE)
CWESourceDescription
CWE-307 cna Improper restriction of excessive authentication attempts
CVSS scores (2)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.3 CRITICAL 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Back to overview