Home

Description

ESC/POS, a printer control language designed by Seiko Epson Corporation, lacks mechanisms for user authentication and command authorization, does not provide controls to restrict sources or destinations of network communication, and transmits commands without encryption or integrity protection.

PUBLISHED Reserved 2026-01-16 | Published 2026-03-05 | Updated 2026-03-06 | Assigner jpcert

Problem types

Missing authentication for critical function

Product status

All products implementing ESC/POS
affected

References

www.epson.jp/support/misc_t/260305_oshirase.htm

download4.epson.biz/...bs/pdf/IP_Filtering_Guide_en_revA.pdf

jvn.jp/en/ta/JVNTA97995322/

cve.org (CVE-2026-23767)

nvd.nist.gov (CVE-2026-23767)

Download JSON