Brother Industries is facing a critical authentication bypass vulnerability affecting hundreds of printer models, primarily used in enterprises. This vulnerability allows unauthenticated remote code execution (RCE) on the devices when combined with another flaw. The issue stems from a manufacturing defect and cannot be resolved through firmware updates, as reported by Rapid7. Additionally, one of the discovered vulnerabilities enables attackers to extract the serial number of a printer, which is a significant concern for the company.
TPRM report: https://scoringcyber.rankiteo.com/company/brother-industries-ltd-
"id": "bro611062825",
"linkid": "brother-industries-ltd-",
"type": "Vulnerability",
"date": "6/2025",
"severity": "25",
"impact": "",
"explanation": "Attack without any consequences: Attack in which data is not compromised"
{'affected_entities': [{'industry': 'Manufacturing',
'name': 'Brother Industries',
'type': 'Corporation'}],
'attack_vector': 'Unauthenticated Remote Code Execution (RCE)',
'description': 'Brother Industries is facing a critical authentication bypass '
'vulnerability affecting hundreds of different printer models, '
'allowing unauthenticated remote code execution (RCE) on the '
'devices when chained with another flaw. The admin password '
'bypass stems from a manufacturing issue and cannot be fixed '
'through firmware. Rapid7, the cybersecurity firm that '
'discovered the vulnerability, identified seven other flaws '
'affecting 689 different device models. One of those '
'vulnerabilities enables attackers to extract the serial '
'number of a printer.',
'impact': {'systems_affected': '689 different printer models'},
'initial_access_broker': {'entry_point': 'Admin password bypass'},
'post_incident_analysis': {'root_causes': 'Manufacturing issue'},
'references': [{'source': 'Rapid7'}],
'response': {'third_party_assistance': 'Rapid7'},
'title': 'Brother Industries Authentication Bypass Vulnerability',
'type': 'Authentication Bypass',
'vulnerability_exploited': ['Admin password bypass',
'Serial number extraction']}