CVE-2023-7326 Details
Description
The Epson Stylus SX510W embedded web management service fails to properly handle consecutive ampersand characters in query parameters when accessing /PRESENTATION/HTML/TOP/INDEX.HTML. A remote attacker can send a malformed request that triggers improper input parsing or memory handling, resulting in the printer process shutting down or powering off, causing a denial of service condition.
A denial-of-service vulnerability has been identified in the Epson Stylus SX510W printer. The issue arises in the embedded web management service, which fails to correctly process consecutive ampersand characters in query parameters when the '/PRESENTATION/HTML/TOP/INDEX.HTML' endpoint is accessed. This flaw allows remote attackers to send malformed requests that disrupt input parsing or memory management, leading to the printer process crashing or the device powering off.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Nov 12, 2025CISA-ADP
Assessed Nov 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.exploit-db.com/exploits/51441 | CISA-ADP | Exploit |
| https://www.epson.eu/en_EU/support/sc/epson-stylus-sx510w/s/s837 | [email protected] | ProductVendor |
| https://www.exploit-db.com/exploits/51441 | [email protected] | Exploit |
| https://www.vulncheck.com/advisories/epson-stylus-printer-remote-power-off-dos | [email protected] | AdvisoryBundleRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Epson Stylus SX510W | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 13, 2025 | CVE Modified | CISA-ADP |
| Nov 12, 2025 | New CVE Received | [email protected] |
Volerion