Vulnerability record · CVE-2023-34260 · published 3 November 2023
CVE-2023-34260: Kyocera TASKalfa 4053ci path traversal causes denial of service
Kyocera · D Copia253mf Plus Firmware
Kyocera TASKalfa 4053ci printers through firmware 2VG_S000.002.561 are vulnerable to path traversal (CWE-22) via a crafted URL using encoded traversal sequences such as /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference like %2fetc%00index.htm. Successful exploitation results in a denial of service (service outage) on the device. The flaw is remotely reachable without authentication or user interaction.
Description
Kyocera TASKalfa 4053ci printers through 2VG_S000.002.561 allow a denial of service (service outage) via /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference such as %2fetc%00index.htm to try to read the /etc directory.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Automated analysis
high priorityCVSS 7.5 (high) with no authentication required, public exploit code available, and very high EPSS probability, though impact is limited to denial of service.
What it is
Kyocera TASKalfa 4053ci printers through firmware 2VG_S000.002.561 are vulnerable to path traversal (CWE-22) via a crafted URL using encoded traversal sequences such as /wlmdeu%2f%2e%2e%2f%2e%2e followed by a directory reference like %2fetc%00index.htm. Successful exploitation results in a denial of service (service outage) on the device. The flaw is remotely reachable without authentication or user interaction.
Impact
An unauthenticated remote attacker can cause a service outage on the affected printer, disrupting printing and potentially other network services provided by the device. There is no evidence in the record of data confidentiality or integrity impact.
Attack surface
The vulnerability is reachable over the network via HTTP requests to the printer's web interface, as indicated by the CVSS vector AV:N/PR:N/UI:N. No authentication or user interaction is required.
Exploitation
No CISA KEV listing is present, but public exploit code is referenced in the Full Disclosure mailing list entry, and EPSS indicates a high probability of exploitation (0.73354, 99.4th percentile).
What to do
- Apply the latest firmware update from Kyocera for the TASKalfa 4053ci; if no fixed version is available, contact the vendor for guidance.
- Restrict network access to the printer's web interface to trusted management hosts or VLANs.
- Disable or block unnecessary web services on the printer if they are not required.
- Monitor vendor advisories for updated firmware and patch promptly.
Detection
- Inspect web server logs for requests containing encoded traversal sequences such as %2e%2e%2f or %00 in the URI path.
- Alert on HTTP requests to paths like /wlmdeu followed by traversal patterns or null bytes.
- Monitor for sudden printer service unavailability or reboots correlated with unusual HTTP requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://sec-consult.com/vulnerability-lab/ | Third Party Advisory |
| https://seclists.org/fulldisclosure/2023/Jul/15 | ExploitMailing ListThird Party Advisory |
| https://sec-consult.com/vulnerability-lab/ | Third Party Advisory |
| https://seclists.org/fulldisclosure/2023/Jul/15 | ExploitMailing ListThird Party Advisory |
Track CVE-2023-34260 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-34260), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.