S4E just found a high top 10 tcp port service scan
critical·Misconfiguration·Updated Jun 28, 2025

CVE-2024-51978 Scanner

CVE-2024-51978 Scanner - Authentication Bypass vulnerability in Brother Printers

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-51978
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
DCP-J928N-W/Bby Brother Industries, Ltd
1.0
MFC-J1800DW (Europe)by Brother Industries, Ltd
1.0
MFC-J1800DW (USA)by Brother Industries, Ltd
1.0
MFC-J4340DWEby Brother Industries, Ltd
1.0
Updated Aug 18, 2026View on NVD →
Detail

Brother Printers are widely used in both consumer and business environments for printing, scanning, and faxing documents. These printers are often integrated into networks, allowing users to print documents remotely and manage the printer settings through a web interface. Brother Printers offer various features such as wireless printing, mobile printing, and cloud connectivity, making them versatile tools in modern office setups. The administrative interface of these printers allows for configuration and management, which is essential for ensuring that the devices are running optimally and securely. With network connectivity, administrators can manage printer settings remotely, which can save time and resources compared to handling these settings directly on the device. Although they are user-friendly and functional, it's crucial that the security settings on Brother Printers are properly configured to prevent unauthorized access.

The Authentication Bypass vulnerability in Brother Printers allows an attacker to gain unauthorized access to the printer by exploiting the default administrator password. This issue arises when the printer's serial number, which can be obtained through simple network queries, is used to generate the default password of the administrator account. The vulnerability is particularly dangerous because it allows remote attackers to take control of the printer without any previous authentication, leading to unauthorized usage and potential misuse. This bypass can be executed using information obtained via unauthenticated HTTP, HTTPS, IPP, SNMP, or PJL requests. This problem highlights the importance of changing default credentials on network devices to prevent unauthorized access.

The technical details of the vulnerability involve manipulating the printer's default administrative password generation process. By obtaining the printer's serial number and using it alongside a known script or algorithm, an attacker can recreate the default administrative password. The process involves a series of character and encoding manipulations that leverage the serial number as an input. This can be accomplished by accessing specific endpoint URLs that reveal the serial number. Additionally, the method requires an understanding of the device's password generation mechanism, which relies heavily on the interaction between JavaScript codes and hashed passwords. Malicious users can use this method to establish a session and gain access through the administrative interface using the default password.

Exploiting the Authentication Bypass vulnerability can lead to several detrimental effects. An unauthorized user could change printer settings, access or alter stored documents, or even use the device for malicious activities such as launching network attacks or disseminating spam. The attacker could potentially disable the printer or alter its configurations to disrupt business operations or steal sensitive corporate data. In some cases, the printer could be used as a proxy for further attacks on the internal network, increasing the risk of significant information compromise. This vulnerability, if exploited, represents a critical security hole that could offer attackers a foothold within a network, potentially compromising other connected devices.

REFERENCES

Solution Advice
  • Change the default administrative password to a strong, unique password immediately after installing the printer.
  • Limit network access to the printer by placing it on a secure, segmented network.
  • Use a Virtual Private Network (VPN) to establish a secure connection when accessing printer settings remotely.
  • Regularly update the printer’s firmware to include security patches and enhancements.
  • Implement network monitoring to detect unusual activity that could indicate an attempted breach or exploit of the printer vulnerability.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.