News
Brother Under Threat: Default Password Exploits Could Compromise Networks
Cybersecurity firm Rapid7 has discovered serious vulnerabilities in Brother Industries' devices, affecting hundreds globally and raising significant security concerns for users

- June 28, 2025
- Updated: July 1, 2025 at 9:16 PM

In a troubling revelation, cybersecurity firm Rapid7 has uncovered a series of significant vulnerabilities impacting hundreds of Brother Industries’ devices, including printers, scanners, and label makers.
The investigation identified eight critical vulnerabilities across 689 models, raising alarms for both home and enterprise users worldwide.
Among these, the most severe flaw, labeled with a CVSS score of 9.8, allows attackers to exploit default passwords to take control of affected devices, potentially gaining access to connected networks.
Cybersecurity Firm Uncovers Serious Flaws in Brother Printers and Scanners
This critical vulnerability, known as CVE-2024-51978, enables unauthorized users to generate a device’s default password by obtaining its serial number, facilitating unauthorized access and control.
Notably, remediation requires more than a software patch; the manufacturing process of these devices needs to be overhauled to ensure the default passwords are securely generated, posing a significant challenge for Brother Industries.
Furthermore, due to Brother’s integral role in the supply chain, several models from other manufacturers, including 46 models from Fujifilm, five from Ricoh, and two from Toshiba, are also impacted by these vulnerabilities. This wide-ranging effect raises concerns across the industry regarding similar vulnerabilities in interconnected devices.
The other identified vulnerabilities enable hackers to retrieve sensitive information, trigger stack-based buffer overflows, force new TCP connections, perform arbitrary HTTP requests, crash devices, and disclose passwords of external configurations.
Rapid7’s collaborative research with JPCERT/CC and Brother Industries aims to inform stakeholders about these critical security flaws and highlight necessary mitigation strategies.
As technology continues to advance, the implications of such vulnerabilities serve as a stark reminder of the importance of cybersecurity in everyday devices. Consumers and businesses alike are encouraged to stay informed about potential risks and consider proactive measures to protect their data and systems.
Journalist specialized in technology, entertainment and video games. Writing about what I'm passionate about (gadgets, games and movies) allows me to stay sane and wake up with a smile on my face when the alarm clock goes off. PS: this is not true 100% of the time.
Latest from Chema Carvajal Sarabia
- Omnisend: The ultimate email and marketing platform for e-commerce now cheaper thanks to Black Friday
- Adobe has just acquired Semrush, the leading brand visibility platform
- The U.S. spy satellites from SpaceX are sending wrong signals
- Google has just sued the Chinese hacker group that stole 1 billion dollars from millions of its users
You may also like
NewsThe director of the short film Marathon assures that AI was not involved in the development of his movie
Read more
NewsWhere Winds Meet has revealed to us what the mortal enemy of wuxia heroes is: the goose
Read more
NewsThe Steam Machine might not cost 500 euros or less, after all
Read more
NewsCall of Duty: Black Ops 7 makes its most interesting addition free for a few days
Read more
NewsTroy Baker is not the protagonist of Intergalactic, but he is making suggestions for the game as if he were
Read more
NewsThe creator of Disco Elysium wants to make a video game about the worst part of humanity
Read more