Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code
Published May 25, 2025
9.8
CRITICALCVSS 3.1
EPSS 0.88%
Description
Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw firmware v05.07 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw/imageCLASS MF455dw/imageCLASS MF453dw/imageCLASS MF452dw/imageCLASS MF451dw/imageCLASS LBP237dw/imageCLASS LBP236dw/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II/imageCLASS X LBP1238 II firmware v05.07 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw/i-SENSYS MF553dw/i-SENSYS MF552dw/i-SENSYS MF455dw/i-SENSYS MF453dw/i-SENSYS LBP236dw/i-SENSYS LBP233dw/imageRUNNER 1643iF II/imageRUNNER 1643i II/i-SENSYS X 1238iF II/i-SENSYS X 1238i II/i-SENSYS X 1238P II/i-SENSYS X 1238Pr II firmware v05.07 and earlier sold in Europe.
Affected products
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
-
- Version 05.07 and earlierStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Canon Inc. | Color imageCLASS LBP632Cdw | n/a |
| ||||||
| Canon Inc. | Color imageCLASS LBP633Cdw | n/a |
| ||||||
| Canon Inc. | Color imageCLASS MF652Cdw | n/a |
| ||||||
| Canon Inc. | Color imageCLASS MF653Cdw | n/a |
| ||||||
| Canon Inc. | Color imageCLASS MF654Cdw | n/a |
| ||||||
| Canon Inc. | Color imageCLASS MF656Cdw | n/a |
| ||||||
| Canon Inc. | Satera MF457dw | n/a |
| ||||||
| Canon Inc. | Satera MF551dw | n/a |
| ||||||
| Canon Inc. | Satera MF654Cdw | n/a |
| ||||||
| Canon Inc. | Satera MF656Cdw | n/a |
| ||||||
| Canon Inc. | i-SENSYS LBP233dw | n/a |
| ||||||
| Canon Inc. | i-SENSYS LBP236dw | n/a |
| ||||||
| Canon Inc. | i-SENSYS LBP631Cdw | n/a |
| ||||||
| Canon Inc. | i-SENSYS LBP633Cdw | n/a |
| ||||||
| Canon Inc. | i-SENSYS MF453dw | n/a |
| ||||||
| Canon Inc. | i-SENSYS MF455dw | n/a |
| ||||||
| Canon Inc. | i-SENSYS MF552dw | n/a |
| ||||||
| Canon Inc. | i-SENSYS MF553dw | n/a |
| ||||||
| Canon Inc. | i-SENSYS MF651Cdw | n/a |
| ||||||
| Canon Inc. | i-SENSYS MF655Cdw | n/a |
| ||||||
| Canon Inc. | i-SENSYS MF657Cdw | n/a |
| ||||||
| Canon Inc. | i-SENSYS X 1238P II | n/a |
| ||||||
| Canon Inc. | i-SENSYS X 1238Pr II | n/a |
| ||||||
| Canon Inc. | i-SENSYS X 1238i II | n/a |
| ||||||
| Canon Inc. | i-SENSYS X 1238iF II | n/a |
| ||||||
| Canon Inc. | imageCLASS LBP236dw | n/a |
| ||||||
| Canon Inc. | imageCLASS LBP237dw | n/a |
| ||||||
| Canon Inc. | imageCLASS MF451dw | n/a |
| ||||||
| Canon Inc. | imageCLASS MF452dw | n/a |
| ||||||
| Canon Inc. | imageCLASS MF453dw | n/a |
| ||||||
| Canon Inc. | imageCLASS MF455dw | n/a |
| ||||||
| Canon Inc. | imageCLASS X LBP1238 II | n/a |
| ||||||
| Canon Inc. | imageCLASS X MF1238 II | n/a |
| ||||||
| Canon Inc. | imageCLASS X MF1643i II | n/a |
| ||||||
| Canon Inc. | imageCLASS X MF1643iF II | n/a |
| ||||||
| Canon Inc. | imageRUNNER 1643i II | n/a |
| ||||||
| Canon Inc. | imageRUNNER 1643iF II | n/a |
|
Configuration 1
- ≤ 05.07
Running on/with
- n/a
Configuration 2
- ≤ 05.07
Running on/with
- n/a
Configuration 3
- ≤ 05.07
Running on/with
- n/a
Configuration 4
- ≤ 05.07
Running on/with
- n/a
Configuration 5
- ≤ 05.07
Running on/with
- n/a
Configuration 6
- ≤ 05.07
Running on/with
- n/a
Configuration 7
- ≤ 05.07
Running on/with
- n/a
Configuration 8
- ≤ 05.07
Running on/with
- n/a
Configuration 9
- ≤ 05.07
Running on/with
- n/a
Configuration 10
- ≤ 05.07
Running on/with
- n/a
Configuration 11
- ≤ 05.07
Running on/with
- n/a
Configuration 12
- ≤ 05.07
Running on/with
- n/a
Configuration 13
- ≤ 05.07
Running on/with
- n/a
Configuration 14
- ≤ 05.07
Running on/with
- n/a
Configuration 15
- ≤ 05.07
Running on/with
- n/a
Configuration 16
- ≤ 05.07
Running on/with
- n/a
Configuration 17
- ≤ 05.07
Running on/with
- n/a
Configuration 18
- ≤ 05.07
Running on/with
- n/a
Configuration 19
- ≤ 05.07
Running on/with
- n/a
Configuration 20
- ≤ 05.07
Running on/with
- n/a
Configuration 21
- ≤ 05.07
Running on/with
- n/a
Configuration 22
- ≤ 05.07
Running on/with
- n/a
Configuration 23
- ≤ 05.07
Running on/with
- n/a
Configuration 24
- ≤ 05.07
Running on/with
- n/a
Configuration 25
- ≤ 05.07
Running on/with
- n/a
Configuration 26
- ≤ 05.07
Running on/with
- n/a
Configuration 27
- ≤ 05.07
Running on/with
- n/a
Configuration 28
- ≤ 05.07
Running on/with
- n/a
Configuration 29
- ≤ 05.07
Running on/with
- n/a
Configuration 30
- ≤ 05.07
Running on/with
- n/a
Configuration 31
- ≤ 05.07
Running on/with
- n/a
Configuration 32
- ≤ 05.07
Running on/with
- n/a
Configuration 33
- ≤ 05.07
Running on/with
- n/a
Configuration 34
- ≤ 05.07
Running on/with
- n/a
Configuration 35
- ≤ 05.07
Running on/with
- n/a
Configuration 36
- ≤ 05.07
Running on/with
- n/a
Configuration 37
- ≤ 05.07
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://canon.jp/support/support-info/250127vulnerability-response vendor-advisoryVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-27695 Advisory
- https://psirt.canon/advisory-information/cp2025-001/ vendor-advisoryVendor Advisory
- https://www.canon-europe.com/support/product-security/#news vendor-advisoryVendor Advisory
- https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://canon.jp/support/support-info/250127vulnerability-response | vendor-advisoryVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-27695 | Advisory | |
| https://psirt.canon/advisory-information/cp2025-001/ | vendor-advisoryVendor Advisory | |
| https://www.canon-europe.com/support/product-security/#news | vendor-advisoryVendor Advisory | |
| https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.