CVE-2019-20458: Epson XP-255
High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a password. The user is at no point prompted to set up a password on the device (leaving a number of devices without a password). In this case, anyone connecting to the web admin panel is capable of becoming admin without using any credentials.
Affected products
- Epson XP-255: version 20.08.fm10i8 only
Published 2024-11-07. Last modified 2026-06-17.