Vulnerability record · CVE-2017-16249 · published 10 November 2017
CVE-2017-16249: Brother Debut HTTP server malformed POST denial of service
Brother · Dcp J132w Firmware
The Debut embedded HTTP server in Brother DCP-J132W firmware hangs when it receives a single malformed HTTP POST request, eventually returning an HTTP 500 after roughly 300 seconds. While hung, network print jobs are blocked and the web interface is unreachable, so a trivial request can take the device out of service.
Description
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with an HTTP 500 error. While the server is hung, print jobs over the network are blocked and the web interface is inaccessible. An attacker can continuously send this malformed request to keep the device inaccessible to legitimate traffic.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityUnauthenticated remote denial of service with public exploit code and high EPSS, but impact is limited to availability of a single device class.
What it is
The Debut embedded HTTP server in Brother DCP-J132W firmware hangs when it receives a single malformed HTTP POST request, eventually returning an HTTP 500 after roughly 300 seconds. While hung, network print jobs are blocked and the web interface is unreachable, so a trivial request can take the device out of service.
Impact
An unauthenticated attacker can render the printer unusable for printing and web management, and can repeat the request to keep it down indefinitely. There is no data confidentiality or integrity impact; the effect is availability loss.
Attack surface
The flaw is reachable over the network through the embedded HTTP server (CVSS vector AV:N/AC:L/PR:N/UI:N), so no authentication or user interaction is required. Any host that can reach the printer's web port can trigger it.
Exploitation
Public exploit code exists (Packet Storm, Exploit-DB, Trustwave references tagged Exploit), and EPSS is high at 0.59 (99th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.
What to do
- Apply the vendor firmware update for the affected Brother DCP-J132W if one is available; check Brother's advisory for the fixed release.
- If no patch exists, isolate printers on a dedicated VLAN and restrict HTTP access to trusted management hosts only.
- Disable or block the embedded web interface and unnecessary print protocols from untrusted networks via firewall rules.
- Monitor and rate-limit HTTP POST traffic to printer management ports to blunt repeated malformed requests.
- Replace end-of-life devices that no longer receive firmware fixes.
Detection
- Alert on HTTP 500 responses or unusually long response times from printer web servers.
- Detect repeated malformed POST requests to printer HTTP ports from a single source.
- Monitor printer availability and print-queue stalls correlated with web interface timeouts.
- Watch for scanning or exploit traffic matching public PoCs against embedded HTTP servers on the network.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/144908/Debut-Embedded-httpd-1.20-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43119/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-017/?fid=10211 | ExploitThird Party Advisory |
| https://www.trustwave.com/Resources/SpiderLabs-Blog/Denial-of-Service-Vulnerability-in-Brother-Printers/?page=1&year=0&m | Third Party Advisory |
| http://packetstormsecurity.com/files/144908/Debut-Embedded-httpd-1.20-Denial-Of-Service.html | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43119/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-017/?fid=10211 | ExploitThird Party Advisory |
| https://www.trustwave.com/Resources/SpiderLabs-Blog/Denial-of-Service-Vulnerability-in-Brother-Printers/?page=1&year=0&m | Third Party Advisory |
Track CVE-2017-16249 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-16249), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.