ProductProduct NewsFujifilm Warns of Path Traversal Vulnerability Affecting Some Printers

Fujifilm Warns of Path Traversal Vulnerability Affecting Some Printers

Fujifilm Business Innovation has disclosed a path traversal vulnerability affecting a wide range of its multifunction devices and printers, and is urging customers to update affected models’ firmware as soon as possible.

In a notice published on 30 September 2026, Fujifilm said it had identified a flaw in the web management interface used by certain multifunction devices and printers. The vulnerability stems from how the interface processes externally supplied parameters, and under specific conditions could let an attacker send a specially crafted request to access information stored on the device, or cause other unintended operations. This type of flaw is commonly known as a path traversal vulnerability.

The issue has been assigned CVE-2026-78249 (CWE-22: Path Traversal), with a CVSSv4 base score of 6.8. Fujifilm said that as of publication, it had not observed any attacks exploiting the vulnerability.

The company credited Jim Rush of Tier Zero Security with discovering and reporting the issue.

Affected Devices 

The vulnerability spans a large portion of Fujifilm’s device lineup, including multiple models across the Apeos, ApeosPrint, ApeosPro and Revoria Press ranges. Affected firmware versions and their fixes differ by region:

Asia (excluding India) and Oceania: roughly two dozen models are affected, including the Apeos 3560/3060/2560 and 3561/3061/2561 series, ApeosPrint 4560S/3960S/3360S, ApeosPro C810/C750/C650, and various Revoria Press models. Fixed firmware versions mostly move from the 1.x branch to patched 1.x releases.

Asia (India), Europe, the Middle East, North America, Latin America and Africa: a smaller but overlapping set of models is listed, including the Apeos 5330/4830, Apeos 5570/4570, Apeos C-series devices, ApeosPrint 5330/4830 and ApeosPrint C4030/C3530, ApeosPro C810/C750/C650, and several Revoria Press models. These regions run on a separate 21.x firmware numbering scheme.

Fujifilm noted that some models are distributed across multiple regions, so customers should check the appropriate table for their device and location.

Actions for MSPs and End Users

Fujifilm’s primary recommendation is to update affected devices to the fixed firmware version listed for each model. Customers in Asia (excluding India) and Oceania can find office printer and multifunction printer support through Fujifilm Business Innovation’s support website, while production and wide-format printer customers, along with all customers in Asia (India), Europe, the Middle East, North America, Latin America and Africa, should contact their local distributor.

Where an immediate firmware update isn’t possible, Fujifilm recommends the following workarounds to reduce risk:

  • Avoid connecting devices directly to the internet, and operate them within a properly protected firewall environment.
  • Always change the default administrator password, using passwords that are sufficiently long and hard to guess.
  • Limit knowledge of administrator passwords to authorised personnel only.
  • If a password may already be widely known, change it promptly.
author avatar
Trish Stevens Head of Content
Trish is the Head of Content for In the Channel Media Group. [email protected]

RELATED ARTICLES

Read our latest magazine