Seiko Epson ESC/POS Command Vulnerability in POS Printers

Vulnerability

A vulnerability exists in the ESC/POS printer control language by Seiko Epson, used for POS printers and related devices. This vulnerability arises from the absence of user authentication and command authorization mechanisms, lack of controls to restrict network communication sources or destinations, and the transmission of commands without encryption or integrity protection. As a result, printers can receive commands from any host on the network, potentially leading to unauthorized access or manipulation of printer functions and data.

Impact

Exploitation of this vulnerability could allow interception of ESC/POS communications, with potential unauthorized execution of commands on the printer or access to information stored on the device.

Remediation

Users are advised to implement authentication and access control measures, restrict network exposure, and encrypt communications when using devices that support ESC/POS.

Added: Mar 5, 2026, 7:26 AM
Updated: Mar 5, 2026, 7:26 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.8
exploitability
4.9
remediation
0.0
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.