CVE-2018-11581: Brother Hl-l2340d Firmware

Medium severity, CVSS 4.8. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via the url parameter to etc/loginerror.html.

Affected products

  • Brother Hl-l2340d Firmware: before 1.16 (fixed in 1.16)
  • Brother Hl-l2380dw Firmware: before 1.16 (fixed in 1.16)

Published 2018-06-01. Last modified 2026-06-17.