Description
The Epson Stylus SX510W embedded web management service fails to properly handle consecutive ampersand characters in query parameters when accessing /PRESENTATION/HTML/TOP/INDEX.HTML. A remote attacker can send a malformed request that triggers improper input parsing or memory handling, resulting in the printer process shutting down or powering off, causing a denial of service condition.
Problem types
CWE-400 Uncontrolled Resource Consumption
Product status
Any version
Timeline
| 2023-05-13: | ExploitDB-51441 is published. |
Credits
Rafael Pedrero
References
www.exploit-db.com/exploits/51441
www.exploit-db.com/exploits/51441
www.epson.eu/en_EU/support/sc/epson-stylus-sx510w/s/s837
www.vulncheck.com/...son-stylus-printer-remote-power-off-dos