CRITICAL · 9.8

CVE-2025-2146

Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product ...

Vulnerability Description

Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw firmware v05.07 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw/imageCLASS MF455dw/imageCLASS MF453dw/imageCLASS MF452dw/imageCLASS MF451dw/imageCLASS LBP237dw/imageCLASS LBP236dw/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II/imageCLASS X LBP1238 II firmware v05.07 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw/i-SENSYS MF553dw/i-SENSYS MF552dw/i-SENSYS MF455dw/i-SENSYS MF453dw/i-SENSYS LBP236dw/i-SENSYS LBP233dw/imageRUNNER 1643iF II/imageRUNNER 1643i II/i-SENSYS X 1238iF II/i-SENSYS X 1238i II/i-SENSYS X 1238P II/i-SENSYS X 1238Pr II firmware v05.07 and earlier sold in Europe.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CanonSatera Mf656Cdw Firmware<= 05.07
CanonSatera Mf656Cdw-
CanonSatera Mf654Cdw Firmware<= 05.07
CanonSatera Mf654Cdw-
CanonSatera Mf551Dw Firmware<= 05.07
CanonSatera Mf551Dw-
CanonSatera Mf457Dw Firmware<= 05.07
CanonSatera Mf457Dw-
CanonImageclass Mf656Cdw Firmware<= 05.07
CanonImageclass Mf656Cdw-
CanonImageclass Mf654Cdw Firmware<= 05.07
CanonImageclass Mf654Cdw-
CanonImageclass Mf653Cdw Firmware<= 05.07
CanonImageclass Mf653Cdw-
CanonImageclass Mf652Cdw Firmware<= 05.07
CanonImageclass Mf652Cdw-
CanonImageclass Lbp633Cdw Firmware<= 05.07
CanonImageclass Lbp633Cdw-
CanonImageclass Lbp632Cdw Firmware<= 05.07
CanonImageclass Lbp632Cdw-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-2146?

CVE-2025-2146 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product ...

How severe is CVE-2025-2146?

CVE-2025-2146 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2025-2146?

Check the references section above for vendor advisories and patch information. Affected products include: Canon Satera Mf656Cdw Firmware, Canon Satera Mf656Cdw, Canon Satera Mf654Cdw Firmware, Canon Satera Mf654Cdw, Canon Satera Mf551Dw Firmware.