Brother Industries, Ltd. Multifunction Printers Improper Certificate Validation Vulnerability Allowing Man-in-the-Middle Attacks

Vulnerability

A vulnerability exists in multiple multifunction printers (MFPs) from Brother Industries, Ltd. These printers do not properly validate server certificates, which could enable a man-in-the-middle attacker to intercept communications and replace the printer's root certificates with arbitrary ones. This flaw could compromise the security of TLS communications by allowing unauthorized CA certificates to be installed on the device.

Impact

Exploitation of this vulnerability could lead to a man-in-the-middle attack, where an attacker could replace the printer's root certificates with malicious ones, potentially compromising TLS communications.

Remediation

Users are advised to update the firmware of their devices. The latest firmware version varies by model and can be downloaded using the Brother Firmware Update Tool. Specific update instructions are available on the Brother support website.

Added: Jan 29, 2026, 4:21 AM
Updated: Jan 29, 2026, 4:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
5.9
remediation
7.7
relevance
2.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.