Published:2026/08/20  Last Updated:2026/08/20

JVNVU#91609598
Multiple SEIKO EPSON printers and scanners keep already revoked root certificates

Overview

Multiple SEIKO EPSON printers and scanners contain revoked root certificates.

Products Affected

A wide range of products are affected.
For more details, refer to the information provided by the developer.

Description

Multiple printers and scanners provided by SEIKO EPSON CORPORATION contain the following vulnerability.

  • Remaining revoked root certificates (CWE-296)
    • CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.3
    • CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Base Score 3.7
    • CVE-2026-73542

Impact

A man-in-the-middle attack may allow an attacker to obtain communication data transmitted by the product.

Solution

Update the root certificates
Update the root certificates in the product according to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Agni Athreya, CyberArch Student Researcher of Carl Vinson Institute of Government at University of Georgia reported this vulnerability to SEIKO EPSON CORPORATION and coordinated. After the coordination was completed, SEIKO EPSON CORPORATION reported the case to JPCERT/CC to notify users of the solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-73542
JVN iPedia