Update Your Printer Firmware Now to Keep Hackers Out

Woman loading paper in a printer.

You keep your computer, phone, and tablet updated with the latest security patches to keep hackers at bay, but what about your printer? With hackers exploiting vulnerabilities, now’s the time to update your printer firmware to keep your network and devices safer.

Hackers Exploiting Printer Vulnerabilities

You don’t usually hear about major hacks involving printers, which is why it’s common for users to just assume they’re safe. But, any device connected to your network or computer is a possible entry point for hackers. Back in June, Rapid7 researchers discovered security vulnerabilities affecting over 700 printer models.

As I write this, hackers are actively exploiting these vulnerabilities to gain control over users’ printers. No, it’s not to use up all your expensive ink. It’s mainly to infect them with malware to use printers as botnets.

Once cybercriminals create a botnet, which is a group of compromised devices, they use the devices to carry out other attacks. These include DDoS attacks (distributed denial of service), cryptocurrency mining, spamming, and even data theft.

So, it’s not just your own devices that are at risk. When you don’t update your printer firmware, your printer could be used to carry out malicious attacks on others. It’s important to note that firmware and software are two different things, so updating your printer software won’t protect you from this threat.

Check to See if Your Printer is Affected

For this current threat, Brother printers are the main target, but that’s not the only brand. Please check the regularly updated list to see if your printer model is affected. This doesn’t mean hackers have already gained access. It just means the vulnerability is there and you need to update your printer firmware now.

Viewing the latest CVE report of affected printers.

Update Your Printer Firmware Easily

Even if your printer isn’t on the list, it’s still a good idea to update the firmware. Depending on your printer manufacturer and setup, firmware may update automatically, but usually you have to confirm the process manually.

The exact process varies based on the printer manufacturer. Typically, there are several common options:

  • Use your printer’s update software, which may be included with the printer software
  • Use a web-based portal using your printer’s IP address (If you’re having trouble connecting your printer via Wi-Fi to access it, try these fixes)
  • Download to a USB drive and insert it directly into the printer
  • Download and run the firmware update while your printer is on and connected
  • Update using your printer’s screen

Since it’s mainly Brother printers affected, I’ll use Brother as an example. Start by visiting your printer manufacturer’s website. Go to the Support section. This could also be the Help, Downloads, or Resources pages depending on the printer brand.

Enter your printer model to search for downloads and resources. Locate your printer model on the printer itself, in the printer settings on your computer, or in your printer’s user manual.

Look for available downloads. Select your operating system, if necessary, then navigate to any firmware downloads.

Downloading firmware update tool from Brother.

In this example, you’d download the Firmware Update Tool that updates firmware online, sending the update directly to your Brother printer.

No matter what your printer manufacturer or model, you should find update files and instructions on the manufacturer’s website.

The update process usually only takes a few minutes. You may need to restart your printer after it’s finished. In some cases, you’ll also have to reconnect it to your device(s) and/or network.

Change Your Printer’s Password

Most printer manufacturers affected by this security vulnerability are releasing firmware updates to fix the issue. But, if an update isn’t available or it doesn’t install for any reason, another way to protect yourself is to change your printer’s password.

By sticking with the default admin password, hackers easily take over your printer simply by reading the model and serial number. If the password is different, it presents an obstacle hackers might not bother with, especially if they’re just trying to create botnets versus accessing your full network.

Changing password for Brother printer.

Once again, the process varies based on your printer manufacturer. There are several common methods:

  • Open your printer’s software/app. Check the Settings area for any privacy or security options. This may let you change the password.
  • Connect to your printer via your web browser. Enter the printer’s IP address and login using the default admin password (found in your user manual and sometimes on the printer itself). Change the password and save your settings.
  • Use your printer’s control panel. Access settings, privacy, or security options from the printer’s menu and change the password from there.

Obviously, hackers don’t just target printers. But, use this incident as a warning as to why you should always update your printer firmware. Also, make sure you’re using antivirus and/or antimalware software to protect your other devices.

Subscribe to our newsletter!

Our latest tutorials delivered straight to your inbox

Crystal Crowder Avatar

Read next

When Cingular chief Stan Sigman backed the original iPhone before its 2007 unveiling, he accepted terms American carriers usually refused: no logo on the device, no control over its software, no preloaded apps, and a share of monthly subscriber revenue flowing back to Apple, after signing on without seeing a prototype
In 2016, archaeologists dated two rings of snapped stalagmites in France’s Bruniquel Cave to 176,500 years ago, evidence that Neanderthals had walked 336 metres into darkness with fire and built architecture deep underground long before modern humans reached Europe
Otto von Bismarck was 74 when Germany adopted the world’s first national old-age social insurance program in 1889, setting the pension age at 70 after years of fighting socialists with bans, laws, and a promise few workers would live long enough to use
When cosmonaut Valeri Polyakov stepped out of his Soyuz capsule in March 1995 after 437 consecutive days aboard Mir, doctors recorded him at several centimetres above his pre-flight height, and his spine had become so unaccustomed to gravity that the recovery team carried him to a chair rather than risk the compression of letting him walk.
When Harvard astronomer Cecilia Payne submitted her 1925 doctoral thesis arguing that the Sun was made almost entirely of hydrogen, the field’s senior figure Henry Norris Russell talked her into adding a line calling the result ‘almost certainly not real,’ and then published the same conclusion himself four years later to widespread acclaim.
When Edme Mariotte stared at marks on a wall in the 1660s, one mark vanished inside a six-degree hole where the optic nerve leaves the eye and the brain has been filling in wallpaper, sky, and faces ever since
When seismic waves from the Chicxulub impact reached what is now North Dakota roughly ten minutes after the asteroid struck, they appear to have triggered a ten-metre standing wave in an inland river that flung fish onto the bank and buried them under glass beads still falling from the sky.
When survivors near Lake Nyos woke on the morning of 22 August 1986, the cattle were dead in the fields, the birds had fallen out of the trees, and 1,746 of their neighbours were lying where they had stood the night before, with no fire, no flood, and no wound to explain it.