CVE-2025-2146

Published May 26, 2025

Last updated a month ago

Overview

Description
Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw firmware v05.07 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw/imageCLASS MF455dw/imageCLASS MF453dw/imageCLASS MF452dw/imageCLASS MF451dw/imageCLASS LBP237dw/imageCLASS LBP236dw/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II/imageCLASS X LBP1238 II firmware v05.07 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw/i-SENSYS MF553dw/i-SENSYS MF552dw/i-SENSYS MF455dw/i-SENSYS MF453dw/i-SENSYS LBP236dw/i-SENSYS LBP233dw/imageRUNNER 1643iF II/imageRUNNER 1643i II/i-SENSYS X 1238iF II/i-SENSYS X 1238i II/i-SENSYS X 1238P II/i-SENSYS X 1238Pr II firmware v05.07 and earlier sold in Europe.
Source
f98c90f0-e9bd-4fa7-911b-51993f3571fd
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

f98c90f0-e9bd-4fa7-911b-51993f3571fd
CWE-787
nvd@nist.gov
CWE-787

Social media

Hype score
Not currently trending
  1. CVE-2025-2146 (CVSS:9.8, CRITICAL) is Undergoing Analysis. Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) whi..https://t.co/3dwInPFDiO #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    31 May 2025

    13 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-2146 (CVSS:9.8, CRITICAL) is Undergoing Analysis. Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) whi..https://t.co/3dwInPFDiO #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    30 May 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-2146 (CVSS:9.8, CRITICAL) is Awaiting Analysis. Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) whi..https://t.co/3dwInPFDiO #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    29 May 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. [ZDI-25-309|CVE-2025-2146] (Pwn2Own) Canon imageCLASS MF656Cdw sfpcmAuthenticateSecAdmin Stack-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.8; Credit: YingMuo (@YingMuo) working with DEVCORE Internship Program.) https://t.co/wTWiT9VzJu

    @TheZDIBugs

    28 May 2025

    1526 Impressions

    1 Retweet

    15 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2025-2146 ⚠️🔴 CRITICAL (9.8) 🏢 Canon Inc. - Satera MF656Cdw 🏗️ 05.07 and earlier 🔗 https://t.co/H7ZnHOo9Rg 🔗 https://t.co/s0hCJSDmKU 🔗 https://t.co/0PUhkdib6P 🔗 https://t.co/o785lLtgss #CyberCron #VulnAlert #InfoSec https://t.co/3oqMO94zaZ

    @cybercronai

    26 May 2025

    46 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. キヤノン製複合機・プリンターに深刻な脆弱性(CVE-2025-2146)CVSS 9.8の境界外書き込み、アップデート必須 #セキュリティ対策Lab #セキュリティ #Security https://t.co/CFXf5t3fcF

    @securityLab_jp

    26 May 2025

    43 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. キヤノンがプリンタのセキュリティ情報を更新し、1月の修正で重大(Critical)な脆弱性CVE-2025-2146が修正されていたことを公表。CVSSスコア9.8のバッファオーバーフロー。日本語版でも情報が出ている。 https://t.co

    @__kokumoto

    26 May 2025

    702 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. CVE-2025-2146 Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment … https://t.co/HIwzkB6uCP

    @CVEnew

    25 May 2025

    678 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. [CVE-2025-2146: CRITICAL] Critical buffer overflow vulnerability discovered in Small Office Multifunction Printers and Laser Printers firmware v05.07 and earlier sold globally, allowing remote attackers to exe...#cve,CVE-2025-2146,#cybersecurity https://t.co/CZ8shzJzNO https://t.

    @CveFindCom

    25 May 2025

    48 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations