CVE-2022-1026 affects Kyocera multifunction printers running vulnerable versions of Net View. The vulnerability is described as an insufficiently protected address book export function that unintentionally exposes sensitive user information, including usernames and passwords. Based on the provided content, the issue allows address book data to be exported without adequate protection, resulting in disclosure of stored credentials and related user information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python exploit script, KyoceraCredsDump.py, plus a README. The script is an operational unauthenticated credential-dumping tool for CVE-2022-1026 affecting Kyocera printers/MFPs. Its purpose is to query the printer's SOAP-based address-book service and extract sensitive stored data, specifically email addresses and credentials for SMB file shares and FTP destinations used by scan workflows. Repository structure is minimal: one code file and one documentation file. The Python script is the clear entry point and includes target parsing, optional pre-flight TCP probing, concurrent exploitation with ThreadPoolExecutor, SOAP request body construction, XML parsing via xmltodict, and formatted output (optionally using rich). The README documents usage and confirms the exploit's intent and CVE mapping. Main capabilities observed: multi-target scanning across single IPs, CIDR blocks, dash ranges, and comma-separated lists; configurable target port (default 9091); optional skipping of liveness probing; concurrent exploitation; extraction and summarization of recovered credentials; and stable sorted reporting of results. This is not merely a detector: it attempts to retrieve real secrets from vulnerable devices. Fingerprintable targeting details include the default TCP service port 9091 and the Kyocera SOAP address-book namespace http://www.kyoceramita.com/ws/km-wsdl/setting/address_book. The exploit also embeds standard SOAP/WS-Addressing XML namespaces in its request bodies. Based on the visible code and README, the exploit is a standalone Python PoC/operational tool rather than part of a larger exploitation framework.
This repository contains a Python proof-of-concept exploit for CVE-2022-1026, targeting legacy Kyocera printers that expose a vulnerable SOAP 1.1 web service. The exploit script (getKyoceraCreds_soap1.1.py) automates the process of sending SOAP requests to enumerate and retrieve the personal address book from the printer, handling device sleep states and retries for reliability. The script parses the responses to extract sensitive information such as login names and passwords, outputs the results to the console in a table, and saves them in a CSV file within the 'kyocera_output' directory. The README provides detailed usage instructions and context about the vulnerability. The main attack vector is network-based, requiring access to the printer's SOAP service (default port 9091). The exploit is a functional PoC and does not include weaponized or post-exploitation payloads.
This repository contains two Nmap Scripting Engine (NSE) scripts written in Lua, each targeting information disclosure vulnerabilities in network printers. 1. 'http-info-xerox-enum.nse' is an enumeration script for Xerox Centreware Internet Services printers. It connects to the printer's web interface (default port 80, customizable via script arguments) and retrieves usernames, hostnames, and document names from the print job history by parsing the '/job/logsys.htm' page. The script is categorized as 'safe' and 'discovery', and is useful for gathering information from accessible Xerox printers. 2. 'http-vuln-cve2022-1026.nse' targets Kyocera multifunction printers vulnerable to CVE-2022-1026. It exploits an insufficiently protected SOAP-based address book export function (typically on port 9090) to extract SMB credentials and email addresses. The script can be run in detection-only mode or full exploitation mode, depending on user arguments. It sends crafted SOAP requests to the '/ws/km-wsdl/setting/address_book' endpoint to enumerate and retrieve sensitive data. The script is categorized as 'exploit' and 'vuln'. Both scripts are operational exploits that leverage network access to printer web interfaces to extract sensitive information, making them valuable for penetration testers and security auditors assessing printer security in enterprise environments.
This repository contains a proof-of-concept Python exploit (getKyoceraCreds.py) targeting CVE-2022-1026, an unauthenticated data extraction vulnerability in Kyocera MFP printers. The exploit leverages the printer's SOAP API, accessible over TCP port 9091, to trigger the export of the address book and retrieve it without authentication. The script parses the returned XML to extract sensitive information, including cleartext credentials for SMB, FTP, and domain accounts, as well as email addresses. The README provides background on the vulnerability, affected models, and usage instructions. The exploit is straightforward, requiring only the target printer's IP address, and demonstrates the risk of exposed management interfaces on networked printers.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.