CVE-2025-22469
7.3SATO Corporation · CL4/6NX Plus and CL4/6NX-J Plus
An OS command injection vulnerability in SATO CL4/6NX Plus printers allows unauthenticated remote attackers to execute arbitrary commands with non-administrative privileges.
Executive summary
SATO CL4/6NX Plus series printers are vulnerable to OS command injection, which permits unauthenticated remote code execution with limited privileges.
Vulnerability
The device suffers from an OS command injection flaw (CWE-78) triggered by improper neutralization of special elements in commands. This vulnerability is remotely exploitable without authentication, allowing an attacker to execute arbitrary OS commands on the affected hardware.
Business impact
The CVSS score of 7.3 reflects a high severity due to the lack of required authentication and the ease of exploitation. Successful exploitation allows an attacker to gain a foothold on the network-connected printer, potentially facilitating lateral movement, reconnaissance, or the disruption of critical labeling and supply chain operations.
Remediation
Immediate Action: Update the firmware on all affected SATO CL4/6NX Plus and CL4/6NX-J Plus devices to version 1.15.5-r1 or higher immediately.
Proactive Monitoring: Monitor network traffic for unusual outbound connections originating from printer segments and review device logs for suspicious system-level command execution attempts.
Compensating Controls: Ensure all printing devices are isolated on a dedicated, non-routable management VLAN and restrict network access to these devices via firewall rules to authorized hosts only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the ability for unauthenticated remote attackers to execute OS commands, this vulnerability poses a significant risk to industrial and logistics environments using SATO hardware. Organizations should prioritize updating firmware across their printer fleet to version 1.15.5-r1 to eliminate this vector of attack.