Cross-Site Request Forgery (CSRF) Vulnerability

Vulnerability Reference: CVE-2026-58315

Description: This is a Cross-Site Request Forgery (CSRF) vulnerability. If a user accesses a malicious website created by a third party, there is a possibility that the settings of the affected device may be altered via the Web Config interface.

Impact: At present, no incidents of this vulnerability being exploited have been confirmed.

    Work Around: To ensure safe and secure use of your product, please refer to our Product Security Page for printers and MFPs.

    Installation and configuration steps are based on the Security Guidebook (Chapter 3)

    1. Do not connect the product directly to the Internet. Instead, install it within a network protected by a firewall. When doing so, use a private IP address.
    2. Always log out after logging in as an administrator. Do not remain logged into Web Config as an administrator for extended periods. Be sure to log out after completing your work.
    3. While logged in as an administrator, do not browse suspicious websites, click untrusted links, open unknown files, or take similar actions.

    Affected Models