CVE-2025-14232
9.8Canon · Satera, Color imageCLASS, imageCLASS X, i-SENSYS, imageRUNNER (Multifunction and Laser Printers)
A buffer overflow vulnerability in the XML processing of XPS files in multiple Canon printer models allows unauthenticated network attackers to execute arbitrary code or crash the system.
Executive summary
A critical buffer overflow vulnerability in various Canon printer models allows unauthenticated remote attackers to execute arbitrary code or cause a denial of service.
Vulnerability
This flaw is an out-of-bounds write (CWE-787) triggered by improper XML processing of XPS files. An unauthenticated attacker located on the same network segment can exploit this memory corruption to achieve remote code execution or render the device unresponsive.
Business impact
The CVSS score of 9.8 reflects the critical nature of this flaw, as it allows full compromise of the device without user interaction or authentication. Successful exploitation could lead to the theft of sensitive print documents, lateral movement within the network, or persistent denial of service, causing significant operational disruption in enterprise environments.
Remediation
Immediate Action: Update the firmware of all affected Canon printer models to a version beyond v06.02 as specified in the official Canon security advisory.
Proactive Monitoring: Monitor network traffic for unusual XML-based requests directed at printer management ports and review device system logs for unexpected reboots or service failures.
Compensating Controls: Restrict access to printer network interfaces using VLANs or firewall rules to ensure that only authorized devices can communicate with the printers, reducing the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the critical severity and the potential for unauthenticated remote code execution, administrators should prioritize firmware updates across all identified printer assets. Verification of the patch deployment is essential to prevent potential exploitation of the affected XML processing component, as this vulnerability provides a direct pathway for attackers to compromise internal network hardware.
More Canon CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Analyst report written