JVNVU#91609598
Multiple SEIKO EPSON printers and scanners keep already revoked root certificates
Overview
Multiple SEIKO EPSON printers and scanners contain revoked root certificates.
Products Affected
A wide range of products are affected.
For more details, refer to the information provided by the developer.
Description
Multiple printers and scanners provided by SEIKO EPSON CORPORATION contain the following vulnerability.
- Remaining revoked root certificates (CWE-296)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.3
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 3.7
- CVE-2026-73542
Impact
A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product.
Solution
Update the root certificates
Update the root certificates in the product according to the information provided by the developer.
Vendor Status
| Vendor | Link |
| SEIKO EPSON CORPORATION | Vulnerability in the Root Certificates of Printers and Scanners (Text in Japanese) |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Agni Athreya, CyberArch Student Researcher of Carl Vinson Institute of Government at University of Georgia reported this vulnerability to SEIKO EPSON CORPORATION and coordinated. After the coordination was completed, SEIKO EPSON CORPORATION reported the case to JPCERT/CC to notify users of the solution through JVN.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-73542 |
| JVN iPedia |
|