HIGH
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Published Jun 15, 2026
7.1
HIGHCVSS 4.0
EPSS 0.46%
Description
Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier
Affected products
-
- Version 1.5.0 or earlierStatusaffectedConstraints-
- Version
-
- Version 1.5.0 or earlierStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Canon Inc. | EOS Network Setting Tool for Windows | unaffected |
| ||||||
| Canon Inc. | EOS Network Setting Tool for macOS | unaffected |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://canon.jp/support/support-info/260615vulnerability-response vendor-advisoryVendor Advisory
- https://psirt.canon/advisory-information/cp2026-005/ vendor-advisoryVendor Advisory
- https://www.canon-europe.com/support/product-security/ vendor-advisoryVendor Advisory
- https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool vendor-advisoryVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://canon.jp/support/support-info/260615vulnerability-response | vendor-advisoryVendor Advisory | |
| https://psirt.canon/advisory-information/cp2026-005/ | vendor-advisoryVendor Advisory | |
| https://www.canon-europe.com/support/product-security/ | vendor-advisoryVendor Advisory | |
| https://www.usa.canon.com/about-us/to-our-customers/cpa2026-005-vulnerability-remediation-for-eos-network-setting-tool | vendor-advisoryVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Canon
Published Jun 15, 2026
Updated Jun 16, 2026
Reserved May 21, 2026
Link CVE-2026-9262
CISA Vulnrichment
Updated Jun 16, 2026