← Back to browse · API

CVE-2024-51977

Severity
MEDIUM
CVSS
5.3
EPSS
0.78001
Risk score
48.5
CISA KEV
No
PoC
No
Published
2025-06-25
Modified
2026-03-30
First seen
2026-08-07
Aliases
EUVD-2024-54705, GHSA-27H4-8C24-MX7W
Products
Brother Industries, Ltd:DCP-1612WR 0 ≤ZB, Brother Industries, Ltd:DCP-1623WR 0 ≤ZB, Brother Industries, Ltd:DCP-7189DW 0 ≤R, Brother Industries, Ltd:DCP-B7520DW (China) A ≤V, Brother Industries, Ltd:DCP-B7520DW 0 ≤V, Brother Industries, Ltd:DCP-B7530DN 0 ≤V, Brother Industries, Ltd:DCP-J1050DW 0 ≤1.14(J), Brother Industries, Ltd:DCP-J1200W(XL) 0 ≤1.15(L), Brother Industries, Ltd:DCP-J914N 0 ≤1.11(J), Brother Industries, Ltd:DCP-L2550DW (Japan) A ≤R, Brother Industries, Ltd:DCP-L2551DN 0 ≤ZC, Brother Industries, Ltd:DCP-L5500DN 0 ≤ZZ, Brother Industries, Ltd:DCP-L5600DN 0 ≤ZZ, Brother Industries, Ltd:DCP-L6600DW 0 ≤ZZ, Brother Industries, Ltd:DCP-T510W(China) A ≤N, Brother Industries, Ltd:DCP-T520W 0 ≤1.21(M), Brother Industries, Ltd:HL-1210WE 0 ≤1.22(T), Brother Industries, Ltd:HL-1210WR 0 ≤1.22(T), Brother Industries, Ltd:HL-1211W 0 ≤1.22(T), Brother Industries, Ltd:HL-J6000CDW 0 ≤S, Brother Industries, Ltd:HL-L2305W 0 ≤1.25(W), Brother Industries, Ltd:HL-L2365DWR 0 ≤1.36(Z), Brother Industries, Ltd:HL-L2371DN 0 ≤1.74(ZE), Brother Industries, Ltd:HL-L2372DN 0 ≤1.74(ZE), Brother Industries, Ltd:HL-L3230CDN 0 ≤1.39(ZA), Brother Industries, Ltd:HL-L5202DW 0 ≤1.82(ZG), Brother Industries, Ltd:HL-L6202DW 0 ≤1.82(ZG), Brother Industries, Ltd:HL-L6300DWT 0 ≤1.95(ZH), Brother Industries, Ltd:HL-L6450DW 0 ≤1.95(ZH), Brother Industries, Ltd:MFC-1912WR 0 ≤V, Brother Industries, Ltd:MFC-J1010DW 0 ≤1.15(K), Brother Industries, Ltd:MFC-J2730DW 0 ≤Y, Brother Industries, Ltd:MFC-J3930DW 0 ≤Z, Brother Industries, Ltd:MFC-J5730DW 0 ≤Y, Brother Industries, Ltd:MFC-J6980CDW 0 ≤S, Brother Industries, Ltd:MFC-J6995CDW 0 ≤S, Brother Industries, Ltd:MFC-J893N 0 ≤X, Brother Industries, Ltd:MFC-L2700DWR 0 ≤Y, Brother Industries, Ltd:MFC-L2730DWR 0 ≤ZC, Brother Industries, Ltd:MFC-L3750CDW 0 ≤ZE, Brother Industries, Ltd:MFC-L5700DN 0 ≤ZZ, Brother Industries, Ltd:MFC-L8610CDW (Japan) A ≤ZD, Brother Industries, Ltd:MFC-L9570CDW (Japan) A ≤ZD, Brother Industries, Ltd:MFC-L9570CDW 0 ≤ZM, Brother Industries, Ltd:RJ-2150 1.0 ≤1.10, Brother Industries, Ltd:SP-1 (Japan) 1.0 ≤1.03(A), Fujifilm Business Innovation:DocuPrint M115 fw 0 ≤M, Fujifilm Business Innovation:DocuPrint M118 w 0 ≤M, RICOH:M 340W 0 ≤G, RICOH:SP 230DNw 0 ≤1.07(G)
Sources
euvd EUVD-2024-54705

Description

An unauthenticated attacker who can access either the HTTP service (TCP port 80), the HTTPS service (TCP port 443), or the IPP service (TCP port 631), can leak several pieces of sensitive information from a vulnerable device. The URI path /etc/mnt_info.csv can be accessed via a GET request and no authentication is required. The returned result is a comma separated value (CSV) table of information. The leaked information includes the device’s model, firmware version, IP address, and serial number.

References