CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-14236

CVSS 9.3v4.0pub. 2026-01-16upd. 2026-01-26

Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.

🤖 AI Analysis
How it works

The vulnerability (CWE-787 — out-of-bounds buffer write) lies in the Address Book attribute tag processing mechanism. An attacker present in the same network segment can send specially crafted data that causes a buffer overflow in the device's memory. As a result, it is possible to overwrite memory areas beyond the intended buffer, leading to device instability or arbitrary code execution (RCE). The attack requires no authentication or user interaction.

Impact

An attacker can execute arbitrary code on the device (RCE) or cause its complete unavailability (no response), leading to loss of confidentiality, integrity, and system availability.

Mitigation & patch

Device firmware should be updated to a version newer than v06.02, applying patches available from the manufacturer according to references: https://psirt.canon/advisory-information/cp2026-001/ (globally), https://canon.jp/support/support-info/260115vulnerability-response (Japan), https://www.usa.canon.com/support/canon-product-advisories/ (USA), https://www.canon-europe.com/support/product-security/ (Europe). Until patches are deployed, it is recommended to isolate devices in a dedicated network segment and restrict network access to printers only for authorized hosts.

Who is affected

Canon devices with firmware v06.02 and earlier: Satera LBP670C Series / Satera MF750C Series (Japan); Color imageCLASS LBP630C / Color imageCLASS MF650C Series / imageCLASS LBP230 Series / imageCLASS X LBP1238 II / imageCLASS MF450 Series / imageCLASS X MF1238 II / imageCLASS X MF1643i II / imageCLASS X MF1643iF II (USA); i-SENSYS LBP630C Series / i-SENSYS MF650C Series / i-SENSYS LBP230 Series / 1238P II / 1238Pr II / i-SENSYS MF450 Series / i-SENSYS MF550 Series / 1238i II / 1238iF II / imageRUNNER 1643i II / imageRUNNER 1643iF II (Europe). Also affects: Canon MF455DW, MF453DW, MF452DW.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Canon Lbp1238 Ii

    HW
    Canon
    all versions
  • Canon Lbp1238 Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp236dw

    HW
    Canon
    all versions
  • Canon Lbp236dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp237dw

    HW
    Canon
    all versions
  • Canon Lbp237dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp632cdw

    HW
    Canon
    all versions
  • Canon Lbp632cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Lbp633cdw

    HW
    Canon
    all versions
  • Canon Lbp633cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1238 Ii

    HW
    Canon
    all versions
  • Canon Mf1238 Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1643if Ii

    HW
    Canon
    all versions
  • Canon Mf1643if Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf1643i Ii

    HW
    Canon
    all versions
  • Canon Mf1643i Ii Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf451dw

    HW
    Canon
    all versions
  • Canon Mf451dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf452dw

    HW
    Canon
    all versions
  • Canon Mf452dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf453dw

    HW
    Canon
    all versions
  • Canon Mf453dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf455dw

    HW
    Canon
    all versions
  • Canon Mf455dw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf652cdw

    HW
    Canon
    all versions
  • Canon Mf652cw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf653cdw

    HW
    Canon
    all versions
  • Canon Mf653cdw Firmware

    OS
    Canon
    ≤ 06.02
  • Canon Mf654cdw

    HW
    Canon
    all versions
  • Canon Mf654cdw Firmware

    OS
    Canon
    ≤ 06.02
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEMemory
CWE
References

Related vulnerabilities

CVE-2025-14234CRITICAL9.3PL ✓same product

Buffer overflow w drukarkach Canon — RCE przez sieć lokalną

CVE-2025-14231CRITICAL9.3PL ✓same product

Buffer overflow w Canon — RCE przez WSD w drukarkach biurowych

CVE-2025-14232CRITICAL9.3PL ✓same product

Buffer overflow w przetwarzaniu XML plików XPS w drukarkach Canon

CVE-2025-14233CRITICAL9.3PL ✓same product

RCE przez invalid free w drukarkach Canon — luki w firmware v06.02

CVE-2025-14235CRITICAL9.3PL ✓same product

Buffer overflow w przetwarzaniu czcionek XPS w drukarkach Canon — RCE