CVE-2020-10670: Canon Oce Colorwave 500 Firmware
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
The web application exposed by the Canon Oce Colorwave 500 4.0.0.0 printer is vulnerable to Reflected XSS in the parameter settingId of the settingDialogContent.jsp page. NOTE: this is fixed in the latest version.
Affected products
- Canon Oce Colorwave 500 Firmware: up to and including 4.0.0.0
Published 2020-03-19. Last modified 2026-06-17.