PaperCut Hive 嵌入式应用(适用于理光设备)中存在输入验证漏洞。该应用在通过 NFC 卡读取过程接收输入时,未对其进行适当清理便将输入传递至应用内嵌的 Web 视图接口。具有物理访问权限的本地攻击者可通过特制的 NFC 卡或 NFC 模拟器利用此漏洞,在应用用户界面上下文中执行任意代码。这可能导致未经授权的操作或信息泄露。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PaperCut | PaperCut Hive | 2.0.0< 2.3.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PaperCut | PaperCut Hive | 2.0.0 ~ 2.3.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-14780 | 7.5 HIGH | PaperCut NG/MF: Remote Code Execution via Scripting Subsystem |
| CVE-2026-82077 | 7.3 HIGH | PaperCut NG/MF: Remote Code Execution via Scan2Fax |
| CVE-2026-87739 | 6.9 MEDIUM | PaperCut MF/NG: User permissions are not evaluated on report generation |
No comments yet