CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-14235

CVSS 9.3v4.0pub. 2026-01-16upd. 2026-01-26

Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.

🤖 AI Analysis
How it works

The vulnerability results from improper validation of fpgm font data contained in XPS (XML Paper Specification) format files processed by the device firmware. An attacker located in the same network segment as the vulnerable device can send a specially crafted XPS document, which causes a buffer overflow (CWE-787) in the device's memory. As a result, it is possible to take control of code execution flow (RCE) or cause the device to become unresponsive.

Impact

An attacker can execute arbitrary code on the vulnerable device (RCE) or cause its complete unavailability. The attack does not require authentication or user interaction, which significantly increases the risk of vulnerability exploitation.

Mitigation & patch

Device firmware must be updated to a version newer than v06.02, in accordance with the manufacturer's recommendations published at: https://psirt.canon/advisory-information/cp2026-001/ (globally), https://canon.jp/support/support-info/260115vulnerability-response (Japan), https://www.usa.canon.com (USA), and https://www.canon-europe.com/support/product-security/ (Europe). Additionally, it is recommended to restrict network access to printing devices through network segmentation and implement firewall rules that prevent unauthorized hosts from communicating with printers.

Who is affected

Canon devices with firmware version v06.02 and earlier: Satera LBP670C / Satera MF750C series (Japan); Color imageCLASS LBP630C / Color imageCLASS MF650C / imageCLASS LBP230 / imageCLASS X LBP1238 II / imageCLASS MF450 / imageCLASS X MF1238 II / imageCLASS X MF1643i II / imageCLASS X MF1643iF II (USA); i-SENSYS LBP630C / i-SENSYS MF650C / i-SENSYS LBP230 / 1238P II / 1238Pr II / i-SENSYS MF450 / i-SENSYS MF550 / 1238i II / 1238iF II / imageRUNNER 1643i II / imageRUNNER 1643iF II (Europe). Also affects products listed in metadata: Canon MF656Cdw, Canon MF653Cdw, Canon MF652Cw.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Canon Lbp1238 Ii

    HW
    Canon
    all versions
  • Canon Lbp1238 Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp236dw

    HW
    Canon
    all versions
  • Canon Lbp236dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp237dw

    HW
    Canon
    all versions
  • Canon Lbp237dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp632cdw

    HW
    Canon
    all versions
  • Canon Lbp632cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp633cdw

    HW
    Canon
    all versions
  • Canon Lbp633cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1238 Ii

    HW
    Canon
    all versions
  • Canon Mf1238 Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1643if Ii

    HW
    Canon
    all versions
  • Canon Mf1643if Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1643i Ii

    HW
    Canon
    all versions
  • Canon Mf1643i Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf451dw

    HW
    Canon
    all versions
  • Canon Mf451dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf452dw

    HW
    Canon
    all versions
  • Canon Mf452dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf453dw

    HW
    Canon
    all versions
  • Canon Mf453dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf455dw

    HW
    Canon
    all versions
  • Canon Mf455dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf652cdw

    HW
    Canon
    all versions
  • Canon Mf652cw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf653cdw

    HW
    Canon
    all versions
  • Canon Mf653cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf654cdw

    HW
    Canon
    all versions
  • Canon Mf654cdw Firmware

    OS
    Canon
    ≤ 06.02
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2025-14234CRITICAL9.3PL ✓same product

Buffer overflow w drukarkach Canon — RCE przez sieć lokalną

CVE-2025-14231CRITICAL9.3PL ✓same product

Buffer overflow w Canon — RCE przez WSD w drukarkach biurowych

CVE-2025-14232CRITICAL9.3PL ✓same product

Buffer overflow w przetwarzaniu XML plików XPS w drukarkach Canon

CVE-2025-14233CRITICAL9.3PL ✓same product

RCE przez invalid free w drukarkach Canon — luki w firmware v06.02

CVE-2025-14236CRITICAL9.3PL ✓same product

Buffer overflow w drukarkach Canon — RCE przez sieć lokalną