← Vulnerability feed

Vulnerability record · CVE-2017-16249 · published 10 November 2017

CVE-2017-16249: Brother Debut HTTP server malformed POST denial of service

Brother · Dcp J132w Firmware

The Debut embedded HTTP server in Brother DCP-J132W firmware hangs when it receives a single malformed HTTP POST request, eventually returning an HTTP 500 after roughly 300 seconds. While hung, network print jobs are blocked and the web interface is unreachable, so a trivial request can take the device out of service.

7.5 CVSS 3.0 High EPSS 59% · top 0.9%
7.5CVSS 3.0 base score, v2 7.8
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated remote denial of service with public exploit code and high EPSS, but impact is limited to availability of a single device class.

What it is

The Debut embedded HTTP server in Brother DCP-J132W firmware hangs when it receives a single malformed HTTP POST request, eventually returning an HTTP 500 after roughly 300 seconds. While hung, network print jobs are blocked and the web interface is unreachable, so a trivial request can take the device out of service.

Impact

An unauthenticated attacker can render the printer unusable for printing and web management, and can repeat the request to keep it down indefinitely. There is no data confidentiality or integrity impact; the effect is availability loss.

Attack surface

The flaw is reachable over the network through the embedded HTTP server (CVSS vector AV:N/AC:L/PR:N/UI:N), so no authentication or user interaction is required. Any host that can reach the printer's web port can trigger it.

Exploitation

Public exploit code exists (Packet Storm, Exploit-DB, Trustwave references tagged Exploit), and EPSS is high at 0.59 (99th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.

What to do

  • Apply the vendor firmware update for the affected Brother DCP-J132W if one is available; check Brother's advisory for the fixed release.
  • If no patch exists, isolate printers on a dedicated VLAN and restrict HTTP access to trusted management hosts only.
  • Disable or block the embedded web interface and unnecessary print protocols from untrusted networks via firewall rules.
  • Monitor and rate-limit HTTP POST traffic to printer management ports to blunt repeated malformed requests.
  • Replace end-of-life devices that no longer receive firmware fixes.

Detection

  • Alert on HTTP 500 responses or unusually long response times from printer web servers.
  • Detect repeated malformed POST requests to printer HTTP ports from a single source.
  • Monitor printer availability and print-queue stalls correlated with web interface timeouts.
  • Watch for scanning or exploit traffic matching public PoCs against embedded HTTP servers on the network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-16249 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2017-16249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.