critical · CVSS v3 9.8 · CVSS v4 6.8
CVE-2026-78249
A path traversal flaw in the web management interface of certain Apeos multifunction devices allows attackers to access arbitrary files. The
Overview
A path traversal flaw in the web management interface of certain Apeos multifunction devices allows attackers to access arbitrary files. The vulnerability can be exploited by sending a crafted request to the device's web server.
Description
A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed, specifically in the handling of externally supplied parameters. If the device receives a specially crafted, malicious request, it may trigger unintended processing.
Impact
Confidentiality: attackers could read sensitive configuration files. Integrity: malicious files could be uploaded or modified. Availability: repeated exploitation may degrade device performance. Device administrators and network operators are directly impacted.
Remediation
Apply the vendor-issued firmware patch that fixes the path-traversal logic. If a patch is unavailable, disable the web management interface or restrict it to trusted IPs via firewall rules. Ensure the device is updated to the latest firmware version.
Risk context
The CVSS v3 score of 9.8 marks this as a critical vulnerability with high exploitation potential. No EPSS data is available, but the severity warrants immediate attention.
Affected products
- Apeos C4571
- Apeos C3567
- Multifunction Devices and Printers
Scores
- Severity
- critical
- CVSS v2
- 5
- CVSS v3
- 9.8
- CVSS v4
- 6.8
- EPSS
- —