Vulnerability record · CVE-2023-34259 · published 3 November 2023
CVE-2023-34259: Kyocera TASKalfa printer path traversal reads arbitrary files
Kyocera · D Copia253mf Plus Firmware
Kyocera TASKalfa 4053ci printers through firmware 2VG_S000.002.561 are vulnerable to directory traversal via the /wlmdeu%2f%2e%2e%2f%2e%2e path, allowing an attacker to read arbitrary files on the filesystem, including files that require root privileges. This is an incomplete fix for CVE-2020-23575, meaning the original traversal flaw was not fully addressed. The issue matters because sensitive configuration or credential files could be exposed, though exploitation requires high privileges.
Description
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Automated analysis
medium priorityThe CVSS score is 4.9 (medium) and exploitation requires high privileges, but the high EPSS score and presence of an exploit reference elevate the risk for exposed printers.
What it is
Kyocera TASKalfa 4053ci printers through firmware 2VG_S000.002.561 are vulnerable to directory traversal via the /wlmdeu%2f%2e%2e%2f%2e%2e path, allowing an attacker to read arbitrary files on the filesystem, including files that require root privileges. This is an incomplete fix for CVE-2020-23575, meaning the original traversal flaw was not fully addressed. The issue matters because sensitive configuration or credential files could be exposed, though exploitation requires high privileges.
Impact
An attacker with high privileges can read arbitrary files on the printer's filesystem, including root-owned files, potentially exposing credentials, configuration, or other sensitive data. There is no impact on integrity or availability.
Attack surface
The vulnerability is reachable over the network via HTTP requests to the /wlmdeu endpoint. According to the CVSS vector, it requires high privileges (PR:H) and no user interaction (UI:N).
Exploitation
No public exploit code is confirmed in the record, but the EPSS probability is 0.60482 (99.1st percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, and reference tags include 'Exploit' from a mailing list, suggesting a proof-of-concept may be available.
What to do
- Apply the latest firmware update from Kyocera that fully addresses the incomplete fix for CVE-2020-23575.
- Restrict network access to the printer's web interface to trusted management networks only.
- Enforce strong authentication and least privilege for printer administrative accounts.
- Monitor for unusual file access patterns or traversal attempts in printer logs.
- Consider disabling the /wlmdeu endpoint if not required for operations.
Detection
- Monitor HTTP requests for encoded directory traversal sequences such as %2e%2e%2f or %2f%2e%2e in URLs targeting the printer's web server.
- Review printer audit logs for unauthorized access to sensitive files or unexpected file read operations.
- Use network monitoring to detect anomalous outbound data transfers from printers that could indicate data exfiltration.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec-consult.com/vulnerability-lab/ | Third Party Advisory |
| https://seclists.org/fulldisclosure/2023/Jul/15 | ExploitMailing ListThird Party Advisory |
| https://sec-consult.com/vulnerability-lab/ | Third Party Advisory |
| https://seclists.org/fulldisclosure/2023/Jul/15 | ExploitMailing ListThird Party Advisory |
Track CVE-2023-34259 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34259), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.