{"id":"CVE-2026-78249","title":"A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed,  specifically in the handling of …","summary":"A path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed,  specifically in the handling of …","severity":"medium","cvss":6.8,"cvssVector":"CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","cwe":["CWE-22"],"vendor":"Fujifilm Business Innovation Corp.","product":"Apeos 3060 / 2560 / 1860 Japan model","affected":["apeos_3060_2560_1860_japan_model 1.50.5 or earlier","apeos_3061_2561_2061_japan_model 1.0.3 or earlier","apeos_4570_3570_japan_model 1.50.5 or earlier","apeos_5330_japan_model 1.50.5 or earlier","apeos_6340_japan_model 1.50.5 or earlier","apeos_7580_6580_5580_japan_model 1.50.5 or earlier","apeos_c2360_c2060_japan_model 1.50.5 or earlier","apeos_c3061_c2561_c2061_japan_model 1.1.103 or earlier","apeos_c3567_c3067_c2567_japan_model 1.1.3 or earlier","apeos_c4030_c3530_japan_model 1.50.5 or earlier","apeos_c5240_japan_model 1.50.5 or earlier","apeos_c7070_c6570_c5570_c4570_c3570_c3070_c2570_japan_model 1.50.5 or earlier","apeos_c7071_c6571_c5571_c4571_c3571_c3071_c2571_japan_model 1.1.3 or earlier","apeos_c8180_c7580_c6580_japan_model 1.50.5 or earlier","apeosprint_4560_s_3960_s_3360_s_japan_model 1.50.5 or earlier","apeosprint_4830_4830_jm_japan_model 1.50.5 or earlier","apeosprint_6340_japan_model 1.50.5 or earlier","apeosprint_c3560_s_c3060_s_japan_model 1.20.105 or earlier","apeosprint_c4030_c3530_japan_model 1.50.5 or earlier","apeosprint_c5240_japan_model 1.50.5 or earlier","apeosprint_c5570_c4570_japan_model 1.50.5 or earlier","apeospro_c810_c750_c650_japan_model 1.50.5 or earlier","revoria_press_e1136_e1125_e1110_e1100_japan_model 1.50.5 or earlier","revoria_press_e1136p_e1125p_e1110p_japan_model 1.50.5 or earlier","revoria_press_ec1100_japan_model 1.22.11 or earlier","revoria_press_ec2100s_ec2100_japan_model 1.1.4 or earlier","revoria_press_sc285s_sc285_japan_model 1.1.0 or earlier","revoriapress_sc180_sc170_japan_model 1.23.6 or earlier","apeos_3560_3060_2560_asia_pacific_model 1.50.5 or earlier","apeos_3561_3061_2561_asia_pacific_model 1.0.3 or earlier","apeos_5330_4830_asia_pacific_model 1.50.5 or earlier","apeos_5570_4570_asia_pacific_model 1.50.5 or earlier","apeos_6340_asia_pacific_model 1.50.5 or earlier","apeos_7580_6580_asia_pacific_model 1.50.5 or earlier","apeos_c3060_c2560_c2060_asia_pacific_model 1.50.5 or earlier","apeos_c3061_c2561_c2061_asia_pacific_model 1.1.103 or earlier","apeos_c3567_c3067_c2567_asia_pacific_model 1.1.3 or earlier","apeos_c4030_c3530_asia_pacific_model 1.50.5 or earlier","apeos_c5240_asia_pacific_model 1.50.5 or earlier","apeos_c7070_c6570_c5570_c4570_c3570_c3070_c2570_asia_pacific_model 1.50.5 or earlier","apeos_c7071_c6571_c5571_c4571_c3571_c3071_c2571_asia_pacific_model 1.1.3 or earlier","apeos_c8180_c7580_c6580_asia_pacific_model 1.50.5 or earlier","apeosprint_4560_s_3960_s_3360_s_asia_pacific_model 1.50.5 or earlier","apeosprint_5330_asia_pacific_model 1.50.5 or earlier","apeosprint_6340_asia_pacific_model 1.50.5 or earlier","apeosprint_c4030_asia_pacific_model 1.50.5 or earlier","apeosprint_c5240_asia_pacific_model 1.50.5 or earlier","apeosprint_c5570_asia_pacific_model 1.50.5 or earlier","apeospro_c810_c750_c650_asia_pacific_model 1.50.5 or earlier","revoria_press_e1136_e1125_e1110_e1100_asia_pacific_model 1.50.5 or earlier"],"published":"2026-10-01","updated":"2026-10-01","sourceUpdated":"2026-10-01T08:16:52.930","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-78249","references":[{"url":"https://global.sharp/corporate/info/product-security/advisory-list/2026-006/","label":"47e4fddc-a2f1-48a0-beab-943c84c1c954"},{"url":"https://www.fujifilm.com/fb/en/news/15736e","label":"47e4fddc-a2f1-48a0-beab-943c84c1c954"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-01T08:40:11.740Z","slug":"CVE-2026-78249","body":"## Overview\n\nA path traversal vulnerability exists in the web management interface of multiple Multifunction Devices and Printers, including Apeos C4571 1.1.3 and earlier, Apeos C3567 1.1.3, or other products listed,  specifically in the handling of externally supplied parameters. \n\nIf the device receives a specially crafted, malicious request, it may trigger unintended processing.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}