← Vulnerability feed

Vulnerability record · CVE-2023-34259 · published 3 November 2023

CVE-2023-34259: Kyocera TASKalfa printer path traversal reads arbitrary files

Kyocera · D Copia253mf Plus Firmware

Kyocera TASKalfa 4053ci printers through firmware 2VG_S000.002.561 are vulnerable to directory traversal via the /wlmdeu%2f%2e%2e%2f%2e%2e path, allowing an attacker to read arbitrary files on the filesystem, including files that require root privileges. This is an incomplete fix for CVE-2020-23575, meaning the original traversal flaw was not fully addressed. The issue matters because sensitive configuration or credential files could be exposed, though exploitation requires high privileges.

4.9 CVSS 3.1 Medium EPSS 60% · top 0.9% CWE-22 · Path traversal
4.9CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow /wlmdeu%2f%2e%2e%2f%2e%2e directory traversal to read arbitrary files on the filesystem, even files that require root privileges. NOTE: this issue exists because of an incomplete fix for CVE-2020-23575.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe CVSS score is 4.9 (medium) and exploitation requires high privileges, but the high EPSS score and presence of an exploit reference elevate the risk for exposed printers.

What it is

Kyocera TASKalfa 4053ci printers through firmware 2VG_S000.002.561 are vulnerable to directory traversal via the /wlmdeu%2f%2e%2e%2f%2e%2e path, allowing an attacker to read arbitrary files on the filesystem, including files that require root privileges. This is an incomplete fix for CVE-2020-23575, meaning the original traversal flaw was not fully addressed. The issue matters because sensitive configuration or credential files could be exposed, though exploitation requires high privileges.

Impact

An attacker with high privileges can read arbitrary files on the printer's filesystem, including root-owned files, potentially exposing credentials, configuration, or other sensitive data. There is no impact on integrity or availability.

Attack surface

The vulnerability is reachable over the network via HTTP requests to the /wlmdeu endpoint. According to the CVSS vector, it requires high privileges (PR:H) and no user interaction (UI:N).

Exploitation

No public exploit code is confirmed in the record, but the EPSS probability is 0.60482 (99.1st percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV, and reference tags include 'Exploit' from a mailing list, suggesting a proof-of-concept may be available.

What to do

  • Apply the latest firmware update from Kyocera that fully addresses the incomplete fix for CVE-2020-23575.
  • Restrict network access to the printer's web interface to trusted management networks only.
  • Enforce strong authentication and least privilege for printer administrative accounts.
  • Monitor for unusual file access patterns or traversal attempts in printer logs.
  • Consider disabling the /wlmdeu endpoint if not required for operations.

Detection

  • Monitor HTTP requests for encoded directory traversal sequences such as %2e%2e%2f or %2f%2e%2e in URLs targeting the printer's web server.
  • Review printer audit logs for unauthorized access to sensitive files or unexpected file read operations.
  • Use network monitoring to detect anomalous outbound data transfers from printers that could indicate data exfiltration.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://sec-consult.com/vulnerability-lab/ Third Party Advisory
https://seclists.org/fulldisclosure/2023/Jul/15 ExploitMailing ListThird Party Advisory
https://sec-consult.com/vulnerability-lab/ Third Party Advisory
https://seclists.org/fulldisclosure/2023/Jul/15 ExploitMailing ListThird Party Advisory

Track CVE-2023-34259 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2023-34260Kyocera TASKalfa 4053ci path traversal causes denial of serviceKyocera TASKalfa 4053ci printers through firmware 2VG_S000.002.561 are vulnerable to path traversal (CWE-22) via a crafted URL using encoded traversa…EPSS 73%analysed7.5CVE-2020-23575Kyocera d-copia253mf plus firmware path traversal vulnerabilityA directory traversal vulnerability exists in Kyocera Printer d-COPIA253MF plus. Successful exploitation of this vulnerability could allow an attacke…EPSS 37%5.3CVE-2023-34261Kyocera d-copia253mf plus firmware information exposure vulnerabilityKyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow identification of valid user accounts via username enumeration because they lead to a…EPSS 8.1%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed

Source: NIST National Vulnerability Database (record CVE-2023-34259), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.