# CVE-2025-35970

## Summary

- **CVE ID:** CVE-2025-35970
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-1391
- **Published:** Aug 7, 2025
- **Last Modified:** Mar 12, 2026

## Description

On multiple products of SEIKO EPSON and FUJIFILM Corporation, the initial administrator password is easy to guess from the information available via SNMP. If the administrator password is not changed from the initial one, a remote attacker with SNMP access can log in to the product with the administrator privilege.

## Affected Products

- SEIKO EPSON — Multiple EPSON product (see the information provided by the vendor)
- FUJIFILM Corporation — FRONTIER DX400W (all versions)

## References

- [CNA](https://www.epson.jp/support/misc_t/250807_oshirase.htm)
- [CNA](https://global.fujifilm.com/en/news/hq/697e)
- [CNA](https://jvn.jp/en/vu/JVNVU91363496/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.45%
- **EPSS Percentile:** 37.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._