CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-14231

CVSS 9.3v4.0pub. 2026-01-16upd. 2026-01-26

Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.

🤖 AI Analysis
How it works

An attacker located in the same network segment as the device can send a specially crafted print job via the WSD protocol. Insufficient input validation leads to buffer overflow (CWE-787 — out-of-bounds write), which allows overwriting memory areas. This can result in device crash or arbitrary code execution in its context.

Impact

An attacker can take control of the device by executing arbitrary code (RCE) or cause permanent device unavailability (denial of service). The attack requires no authentication or user interaction.

Mitigation & patch

Firmware on affected devices should be updated to a version newer than v06.02, applying patches available from the manufacturer in accordance with the references (https://psirt.canon/advisory-information/cp2026-001/). Until the patch is deployed, it is recommended to isolate devices in a dedicated network segment and restrict access to them only to trusted hosts using firewall rules.

Who is affected

Firmware v06.02 and earlier in the following product lines: Satera LBP670C Series / Satera MF750C Series (Japan); Color imageCLASS LBP630C / Color imageCLASS MF650C Series / imageCLASS LBP230 Series / imageCLASS X LBP1238 II / imageCLASS MF450 Series / imageCLASS X MF1238 II / imageCLASS X MF1643i II / imageCLASS X MF1643iF II (USA); i-SENSYS LBP630C Series / i-SENSYS MF650C Series / i-SENSYS LBP230 Series / 1238P II / 1238Pr II / i-SENSYS MF450 Series / i-SENSYS MF550 Series / 1238i II / 1238iF II / imageRUNNER 1643i II / imageRUNNER 1643iF II (Europe). Products listed in metadata: Canon MF455DW, MF453DW, MF452DW.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Canon Lbp1238 Ii

    HW
    Canon
    all versions
  • Canon Lbp1238 Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp236dw

    HW
    Canon
    all versions
  • Canon Lbp236dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp237dw

    HW
    Canon
    all versions
  • Canon Lbp237dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp632cdw

    HW
    Canon
    all versions
  • Canon Lbp632cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp633cdw

    HW
    Canon
    all versions
  • Canon Lbp633cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1238 Ii

    HW
    Canon
    all versions
  • Canon Mf1238 Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1643if Ii

    HW
    Canon
    all versions
  • Canon Mf1643if Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1643i Ii

    HW
    Canon
    all versions
  • Canon Mf1643i Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf451dw

    HW
    Canon
    all versions
  • Canon Mf451dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf452dw

    HW
    Canon
    all versions
  • Canon Mf452dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf453dw

    HW
    Canon
    all versions
  • Canon Mf453dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf455dw

    HW
    Canon
    all versions
  • Canon Mf455dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf652cdw

    HW
    Canon
    all versions
  • Canon Mf652cw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf653cdw

    HW
    Canon
    all versions
  • Canon Mf653cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf654cdw

    HW
    Canon
    all versions
  • Canon Mf654cdw Firmware

    OS
    Canon
    ≤ 06.02
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2025-14235CRITICAL9.3PL ✓same product

Buffer overflow w przetwarzaniu czcionek XPS w drukarkach Canon — RCE

CVE-2025-14232CRITICAL9.3PL ✓same product

Buffer overflow w przetwarzaniu XML plików XPS w drukarkach Canon

CVE-2025-14233CRITICAL9.3PL ✓same product

RCE przez invalid free w drukarkach Canon — luki w firmware v06.02

CVE-2025-14234CRITICAL9.3PL ✓same product

Buffer overflow w drukarkach Canon — RCE przez sieć lokalną

CVE-2025-14236CRITICAL9.3PL ✓same product

Buffer overflow w drukarkach Canon — RCE przez sieć lokalną