CVE-2019-10880: Xerox Colorqube 8700 Firmware

Critical severity, CVSS 9.8. EPSS: 8.5% chance of exploitation in the next 30 days.

Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.

Affected products

  • Xerox Colorqube 8700 Firmware: before 072.161.009.07200 (fixed in 072.161.009.07200)
  • Xerox Colorqube 8900 Firmware: before 072.161.009.07200 (fixed in 072.161.009.07200)
  • Xerox Colorqube 9301 Firmware: before 072.180.009.07200 (fixed in 072.180.009.07200)
  • Xerox Colorqube 9302 Firmware: before 072.180.009.07200 (fixed in 072.180.009.07200)
  • Xerox Colorqube 9303 Firmware: before 072.180.009.07200 (fixed in 072.180.009.07200)

Published 2019-04-12. Last modified 2026-06-17.