CVE-2025-14233

9.8

Canon · Small Office Multifunction Printers and Laser Printers

A memory corruption vulnerability in Canon printer firmware allows unauthenticated attackers on the network to cause a denial of service or execute arbitrary code via invalid file deletion processing.

Executive summary

A critical remote code execution vulnerability exists in various Canon printer models that could allow unauthenticated network attackers to gain full control over the device.

Vulnerability

The flaw is an invalid free vulnerability (CWE-763) triggered during the CPCA file deletion process. This allows an unauthenticated attacker positioned on the local network segment to trigger a crash or achieve arbitrary code execution.

Business impact

The potential for remote code execution on these devices presents a severe risk to organizational security, as compromised printers can serve as a persistent foothold for lateral movement within the internal network. Given the CVSS score of 9.8, this vulnerability is classified as critical, as it allows full system compromise without requiring any user interaction or authentication.

Remediation

Immediate Action: Administrators must verify the firmware version of all affected Canon Satera, imageCLASS, and i-SENSYS printers and apply the latest available firmware update provided by Canon as soon as it is released.

Proactive Monitoring: Monitor network traffic for unusual activity originating from printer subnets, particularly traffic directed at administrative ports or unexpected outbound connections.

Compensating Controls: Segment printer devices onto a dedicated, isolated VLAN with strict firewall rules to restrict access to only authorized management endpoints, thereby limiting the exposure to potential network-based attackers.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this vulnerability and the potential for total system compromise, organizations should treat this as a high-priority update. It is essential to identify all vulnerable printer inventory and ensure that firmware update procedures are scheduled immediately upon the availability of vendor-supplied patches to prevent potential exploitation.

More Canon CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written

Sources