CVE-2026-23767CRITICAL 9.8EPSS p35.5%
CVE-2026-23767CVE-2026-23767
Description
ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.45% probability of exploitation · percentile 35.5% · 2026-06-19T12:03:05Z |
| Published | 2026-03-05 |
| Last modified | 2026-03-09 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Missing Authentication for Critical Functioncwe-306 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.