CVE-2013-2670: Brother Mfc-9970cdw

Medium severity, CVSS 4.3. EPSS: 2% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in the Brother MFC-9970CDW printer with firmware G (1.03) and L (1.10) allows remote attackers to inject arbitrary web script or HTML via an arbitrary parameter name (QUERY_STRING) to admin/admin_main.html, a different vulnerability than CVE-2013-2507 and CVE-2013-2671.

Affected products

  • Brother Mfc-9970cdw
  • Brother Mfc-9970cdw Firmware: version g(1.03) only; version l(1.10) only

Published 2014-03-14. Last modified 2026-06-16.