DFIELDSOLUTIONS

Case study · 2025 · Security

An old print server, sitting forgotten on the network.Demoed a working exploit in four seconds. The team saw that anyone outside could have taken the print server over completely.

CVE-2023-27350 is a PaperCut MF/NG authentication-bypass flaw (CVSS 9.8). The studio's PoC chains the SetupCompleted bypass with the Print Scripting console, then drops a Windows SYSTEM-level reverse shell · end-to-end recon → exploit → shell, in 4 seconds, scripted in Python.

  • Python
  • requests
  • PaperCut MF/NG
  • Netcat
Internal build, no public URL
CVE-2023-27350 · PaperCut RCE PoC

Inside the build

CVE-2023-27350 · PaperCut RCE PoC — Opening state
Opening state
CVE-2023-27350 · PaperCut RCE PoC — In use
In use
CVE-2023-27350 · PaperCut RCE PoC — Result
Result

Overview

9.8
CVSS score
1
HTTP POST to bypass
4 sec
Recon → SYSTEM shell
SYSTEM
Reverse shell privilege

PoC exploiting the PaperCut MF/NG authentication-bypass flaw (CVSS 9.8). The SetupCompleted page skips auth, and the Print Scripting console runs arbitrary code from there · our script chains both and drops a Windows SYSTEM-level reverse shell on the attacker machine. Full end-to-end demo: recon, payload, shell.

What shipped

What it does

  • Exploits PaperCut MF/NG below 20.1.7 / 21.2.11 / 22.0.9
  • Python PoC · 1 HTTP POST to bypass, 1 to run code
  • SYSTEM / root reverse shell back to the attacker box
  • Clean recon → exploit → shell demo in 4 seconds

The problem

  • Print servers rarely get security audits yet sit in the middle of the network
  • 'Hidden' admin pages are often reachable without auth, SetupCompleted is the textbook case
  • Print Scripting runs JS-spawned processes with no sandbox · that becomes SYSTEM

Why it matters

  • Concrete proof that a forgotten PaperCut box gets owned in minutes
  • Shows why closing ports isn't the fix · logic flaws are the real attack surface
  • Exact remediation path: upgrade to 20.1.7 / 21.2.11 / 22.0.9+ and segment the print LAN

How it shipped

  1. 01 · RECON

    Identify the vulnerable PaperCut server.

    Banner-grab the build version via the management UI · everything below 20.1.7 / 21.2.11 / 22.0.9 is in scope. Print servers usually sit unsegmented in the middle of internal LANs.

  2. 02 · BYPASS

    SetupCompleted skips auth.

    A single POST to the SetupCompleted handler walks the server past authentication into an admin-equivalent state. The PoC sends one request and is in.

  3. 03 · SHELL

    Print Scripting → SYSTEM reverse shell.

    Print Scripting console runs JS-spawned processes with no sandbox · cmd.exe under SYSTEM privilege. Netcat catches the reverse shell on the attacker box.

Stack

PoC

Python script · 1 POST to bypass, 1 to run code

Two-call exploit · simple, repeatable, demo-friendly. Authorisation: defensive research, lab-only.

Demo

Recon → exploit → shell in 4 seconds

Live capture shows how fast a forgotten PaperCut box gets owned · concrete proof for asset-management conversations.

Remediation

Patch path + LAN segmentation note

Upgrade to 20.1.7 / 21.2.11 / 22.0.9+, segment the print LAN, restrict the management UI to ops-only · documented alongside the PoC.

Lessons

Logic flaws beat port-closing

Closing the firewall isn't enough · the SetupCompleted page is reachable behind the firewall too. Auth-bypass at the application layer is the real attack surface.

Case study

“We had a 'firewall closes everything, we're fine' attitude and a print server we'd forgotten existed. The proof-of-concept took four seconds, and showed our security team that someone from outside could take the whole thing over completely. The patch and the network split we'd been arguing about for months happened the next week. Sobering, but exactly what we needed.”

Anonymous · SOC lead · enterprise (defensive research engagement) · GB

More work

DField Solutions · DField Bt. · dezso@dfieldsolutions.com
5.0
“From LinkedIn DM to live site. Two tiny tweaks, then shipped.”Michael J Ringer · Vilya ProtectionFounder · Spain