CVE-2025-8452 Overview
CVE-2025-8452 is an information disclosure vulnerability affecting Brother multi-function printers that implement Brother-provided firmware. Attackers on the local network can query the uscan protocol defined by the eSCL (eScanner Communication Language) specification to retrieve the device serial number. That serial number can then be combined with CVE-2024-51978 to derive the default administrator password. The flaw mirrors CVE-2024-51977, differing only in the discovery protocol used. Any eSCL-aware discovery service, including the runZero Explorer, can trigger the disclosure.
Critical Impact
Adjacent-network attackers can extract printer serial numbers via uscan/eSCL and chain the data with CVE-2024-51978 to compute the unchanged default administrator password.
Affected Products
- Brother multi-function printers running Brother-provided firmware that exposes the eSCL uscan service
- Devices retaining the factory default administrator password
- Networks where the eSCL discovery endpoint is reachable on the local segment
Discovery Timeline
- 2025-08-12 - CVE-2025-8452 published to NVD
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-8452
Vulnerability Analysis
The vulnerability is categorized under CWE-538: Insertion of Sensitive Information into Externally-Accessible File or Directory. Brother firmware exposes the eSCL uscan endpoint, a standards-based protocol used for networked document scanning. Within the eSCL capability response, the device discloses the serial number of the multi-function printer. Serial numbers are not sensitive in isolation, but Brother firmware derives the default administrator password from the serial number through the algorithm documented in CVE-2024-51978. An adjacent-network attacker who reads the serial number can therefore reconstruct the device's default credentials without authentication. The attack scope is confined to the local network, as the eSCL interface is not typically routed to the internet.
Root Cause
Brother firmware embeds the device serial number in the publicly reachable eSCL capability document and simultaneously relies on that serial number as seed material for the default administrator password. The design assumes serial numbers are not externally discoverable, so no authentication is enforced on the uscan endpoint. Any eSCL-compliant scanner discovery query returns the identifier.
Attack Vector
An attacker on the adjacent network issues a standard eSCL discovery request to the printer. Tools that already implement the specification, including the runZero Explorer, will return the serial number as part of normal asset enumeration. The attacker feeds the serial number into the CVE-2024-51978 password derivation routine and logs in to the printer's administrative interface. No user interaction and no prior privileges are required.
No verified exploit code has been published for this issue. See the Rapid7 vulnerability advisory and the Brother support FAQ for vendor-provided technical context.
Detection Methods for CVE-2025-8452
Indicators of Compromise
- Unexpected eSCL uscan HTTP requests to Brother printers from hosts that are not sanctioned asset inventory tools.
- Administrative logons to Brother printers originating from workstations that have never previously managed the device.
- Configuration changes on Brother printers immediately following eSCL discovery scans on the subnet.
Detection Strategies
- Inspect printer HTTP access logs for GET /eSCL/ScannerCapabilities requests and correlate the source address against approved scanner inventories.
- Alert on repeated eSCL queries across multiple Brother devices from a single internal host, which indicates serial-number harvesting.
- Baseline normal eSCL traffic volumes so that enumeration bursts stand out against routine scanning activity.
Monitoring Recommendations
- Capture network flow data on VLANs hosting multi-function printers and flag unauthorized access to TCP ports used by eSCL.
- Monitor Brother administrative logins and treat any session from the derived default password as a compromise indicator.
- Feed printer syslog and HTTP access logs into a centralized analytics platform to retain discovery-protocol activity for investigation.
How to Mitigate CVE-2025-8452
Immediate Actions Required
- Change the default administrator password on every Brother multi-function printer; this single action neutralizes the credential derivation chain.
- Inventory Brother devices exposing the eSCL uscan endpoint and restrict management access to a dedicated administration VLAN.
- Block external and untrusted-segment access to printer HTTP, HTTPS, and eSCL ports at the network boundary.
Patch Information
Brother has published guidance for affected models through the Brother support FAQ. Apply the firmware updates listed by the vendor for each affected product. Rapid7's consolidated advisory tracks the full set of Brother device vulnerabilities disclosed alongside this one. According to the vendor, changing the default administrator password renders this specific vulnerability ineffective because the derived password is no longer valid.
Workarounds
- Rotate the administrator password on every Brother printer to a strong, unique value stored in a password manager.
- Disable eSCL/uscan on devices that do not require network scanning functionality.
- Segment printers onto a management VLAN with ACLs permitting only sanctioned print servers and asset discovery scanners.
- Restrict asset discovery tools, including runZero Explorer deployments, to authorized operator accounts and audited scan windows.
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.