Brother printers that are connected to a network are vulnerable to a Denial-Of-Service (DOS) attack through the printer’s embedded web server (called “Debut”).
Of course, the attacker must have the ability to access the printer’s Web Server.
- No Brother printer should be exposed to the Internet.
- You should also put Brother printers on their own network with a VLAN to prevent internal DOS attacks.
There is no fix available from Brother, nor has Brother replied to the bug submission. The problem was first detected by TrustWave here: https://www.trustwave.com/Resources/SpiderLabs-Blog/Denial-of-Service-Vulnerability-in-Brother-Printers/
TrustWave submitted proof of concept code (Python) here: https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2017-017/?fid=10211