PoC Index

CVE-2024-51978

CRITICAL 9.8EPSS 18.7%

An unauthenticated attacker who knows the target device's serial number, can generate the default administrator password for the device. An unauthenticated attacker can first discover the target device's serial number via CVE-2024-51977 over HTTP/HTTPS/IPP, or via a PJL request, or via an SNMP request.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
18.70% chance of exploitation in the next 30 days, 97th percentile
Nuclei
critical · CWE-1391
Published
2025-06-25
Updated
2026-03-30

Proof-of-concept exploits (3)

Nuclei templates (1)

References

Related