Dear Customers,
Thank you very much for your continued support of our products.
We have identified a path traversal vulnerability affecting certain models of our multifunction devices and printers. Under specific conditions, this issue could allow information stored on the device to be inappropriately accessed via a “path traversal” technique. At the time of publication, we have not observed any attacks exploiting this vulnerability. To help you continue using our products with confidence, please review the information below and take the recommended actions.
A vulnerability exists in the implementation that processes externally supplied parameters in the web management interface provided by the affected product. An attacker may be able to cause unintended operations to be executed by sending a specially crafted request.
This issue corresponds to what is commonly referred to as a “path traversal vulnerability.”
We will provide firmware updates that address this vulnerability.
Please refer to the “Affected Product List” at the end of this notice for product names, affected versions, and fixed versions.
For more information on how to update the firmware, please refer to the “Contact” section below.
If updating the firmware is difficult, you can reduce risk by implementing the workaround below.
Appropriate installation practices and operational controls significantly reduce the risk of unauthorized access to the device.
- Operate the device within a properly protected firewall environment.
- Always change the default administrator password.
- Use passwords that are sufficiently long and hard to guess.
- Limit knowledge of administrator passwords to personnel with proper authorization only.
- If a password may already be widely known, change it promptly.
- CVE-2026-78249 (CWE-22: Path Traversal)
CVSSv4 base score 6.8
AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
We would like to express our gratitude to Jim Rush at Tier Zero Security for the finding of the vulnerability.
Office Printers and Multifunction Printers
For further information and support, please refer to FUJIFILM Business Innovation support website for more details:
Production Printers and Wide Format Printers
Please contact the local distributors.
Please contact the local distributors.
The names of the affected products, their versions, and their fixed firmware versions are listed below. Please refer to the table of correct regions for some models are distributed in multiple regions.
- Asia (excluding India), Oceania
- Asia (India), Europe, the Middle East, North America, Latin America, and Africa
| Product Name | Affected Firmware Version | Fixed Firmware Version |
|---|---|---|
| Apeos 3560 / 3060 / 2560 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos 3561 / 3061 / 2561 | 1.0.3 or earlier | 1.0.4 or later |
| Apeos 55330 / 4830 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos 5570 / 4570 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos 6340 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos 7580 / 6580 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos C3060 / C2560 / C2060 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos C3061 / C2561 / C2061 | 1.1.103 or earlier | 1.2.0 or later |
| Apeos C3567 / C3067 / C2567 | 1.1.3 or earlier | 1.2.0 or later |
| Apeos C4030/C3530 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos C5240 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos C7070 / C6570 / C5570 / C4570 / C3570 / C3070 / C2570 | 1.50.5 or earlier | 1.50.6 or later |
| Apeos C7071 / C6571 / C5571 / C4571 / C3571 / C3071 / C2571 | 1.1.3 or earlier | 1.2.0 or later |
| Apeos C8180 / C7580 / C6580 | 1.50.5 or earlier | 1.50.6 or later |
| ApeosPrint 4560 S / 3960 S / 3360 S | 1.50.5 or earlier | 1.50.6 or later |
| ApeosPrint 5330 | 1.50.5 or earlier | 1.50.6 or later |
| ApeosPrint 6340 | 1.50.5 or earlier | 1.50.6 or later |
| ApeosPrint C4030 | 1.50.5 or earlier | 1.50.6 or later |
| ApeosPrint C5240 | 1.50.5 or earlier | 1.50.6 or later |
| ApeosPrint C5570 | 1.50.5 or earlier | 1.50.6 or later |
| ApeosPro C810 / C750 / C650 | 1.50.5 or earlier | 1.50.6 or later |
| Revoria Press E1136 / E1125/ E1110 / E1100 | 1.50.5 or earlier | 1.50.6 or later |
| Revoria Press EC1100 | 1.22.11 or earlier | 1.22.12 or later |
| Revoria Press EC2100S / EC2100 | 1.1.4 or earlier | 1.3.0 or later |
| Revoria Press SC285S / SC285 | 1.1.0 or earlier | 1.2.0 or later |
| RevoriaPress SC180 / SC170 | 1.23.6 or earlier | 1.23.7 or later |
| Product Name | Affected Firmware Version | Fixed Firmware Version |
|---|---|---|
| Apeos 3561 / 3061 / 2561 | 1.0.3 or earlier | 1.0.4 or later |
| Apeos 5330 / 4830 | 21.50.4 or earlier | 21.50.7 or later |
| Apeos 5570 / 4570 | 21.50.5 or earlier | 21.50.7 or later |
| Apeos C3060 / C2560 / C2060 | 21.50.4 or earlier | 21.50.7 or later |
| Apeos C3060 / C2560 / C2060 | 21.50.4 or earlier | 21.50.7 or later |
| Apeos C4030/C3530 | 21.50.4 or earlier | 21.50.7 or later |
| Apeos C7070 / C6570 / C5570 / C4570 / C3570 / C3070 | 21.50.5 or earlier | 21.50.7 or later |
| ApeosPrint 5330/4830 | 21.50.4 or earlier | 21.50.7 or later |
| ApeosPrint C4030/C3530 | 21.50.4 or earlier | 21.50.7 or later |
| ApeosPro C810 / C750 / C650 | 21.50.5 or earlier | 21.50.7 or later |
| Revoria Press E1136 / E1125/ E1110 / E1100 | 21.50.5 or earlier | 21.50.7 or later |
| Revoria Press EC1100 | 21.1.6 or earlier | 21.1.7 or later |
| Revoria Press EC2100S / EC2100 | 21.1.4 or earlier | 21.3.0 or later |
| Revoria Press SC285S / SC285 | 21.1.0 or earlier | 21.2.0 or later |
| RevoriaPress SC180 / SC170 | 21.1.4 or earlier | 21.1.5 or later |
Note: Some models are distributed across multiple regions.


