9.8
CRITICAL
CVE-2025-2146
Canon Printers Buffer Overflow Vulnerability
Description

Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw firmware v05.07 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw/imageCLASS MF455dw/imageCLASS MF453dw/imageCLASS MF452dw/imageCLASS MF451dw/imageCLASS LBP237dw/imageCLASS LBP236dw/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II/imageCLASS X LBP1238 II firmware v05.07 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw/i-SENSYS MF553dw/i-SENSYS MF552dw/i-SENSYS MF455dw/i-SENSYS MF453dw/i-SENSYS LBP236dw/i-SENSYS LBP233dw/imageRUNNER 1643iF II/imageRUNNER 1643i II/i-SENSYS X 1238iF II/i-SENSYS X 1238i II/i-SENSYS X 1238P II/i-SENSYS X 1238Pr II firmware v05.07 and earlier sold in Europe.

INFO

Published Date :

May 26, 2025, 12:15 a.m.

Last Modified :

June 3, 2025, 3:49 p.m.

Source :

f98c90f0-e9bd-4fa7-911b-51993f3571fd

Remotely Exploitable :

Yes !

Impact Score :

5.9

Exploitability Score :

3.9
Affected Products

The following products are affected by CVE-2025-2146 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Canon i-sensys_lbp633cdw_firmware
2 Canon i-sensys_lbp633cdw
3 Canon satera_mf656cdw_firmware
4 Canon satera_mf656cdw
5 Canon satera_mf654cdw_firmware
6 Canon satera_mf654cdw
7 Canon satera_mf551dw_firmware
8 Canon satera_mf551dw
9 Canon satera_mf457dw_firmware
10 Canon satera_mf457dw
11 Canon imageclass_mf656cdw_firmware
12 Canon imageclass_mf656cdw
13 Canon imageclass_mf654cdw_firmware
14 Canon imageclass_mf654cdw
15 Canon imageclass_mf653cdw_firmware
16 Canon imageclass_mf653cdw
17 Canon imageclass_mf652cdw_firmware
18 Canon imageclass_mf652cdw
19 Canon imageclass_lbp633cdw_firmware
20 Canon imageclass_lbp633cdw
21 Canon imageclass_lbp632cdw_firmware
22 Canon imageclass_lbp632cdw
23 Canon imageclass_mf455dw_firmware
24 Canon imageclass_mf455dw
25 Canon imageclass_mf453dw_firmware
26 Canon imageclass_mf453dw
27 Canon imageclass_mf452dw_firmware
28 Canon imageclass_mf452dw
29 Canon imageclass_mf451dw_firmware
30 Canon imageclass_mf451dw
31 Canon imageclass_lbp237dw_firmware
32 Canon imageclass_lbp237dw
33 Canon imageclass_lbp236dw_firmware
34 Canon imageclass_lbp236dw
35 Canon imageclass_x_mf1238_ii_firmware
36 Canon imageclass_x_mf1238_ii
37 Canon imageclass_x_mf1643i_ii_firmware
38 Canon imageclass_x_mf1643i_ii
39 Canon imageclass_x_mf1643if_ii_firmware
40 Canon imageclass_x_mf1643if_ii
41 Canon imageclass_x_lbp1238_ii_firmware
42 Canon imageclass_x_lbp1238_ii
43 Canon i-sensys_mf657cdw_firmware
44 Canon i-sensys_mf657cdw
45 Canon i-sensys_mf655cdw_firmware
46 Canon i-sensys_mf655cdw
47 Canon i-sensys_mf651cdw_firmware
48 Canon i-sensys_mf651cdw
49 Canon i-sensys_lbp631cdw_firmware
50 Canon i-sensys_lbp631cdw
51 Canon i-sensys_mf553dw_firmware
52 Canon i-sensys_mf553dw
53 Canon i-sensys_mf552dw_firmware
54 Canon i-sensys_mf552dw
55 Canon i-sensys_mf455dw_firmware
56 Canon i-sensys_mf455dw
57 Canon i-sensys_mf453dw_firmware
58 Canon i-sensys_mf453dw
59 Canon i-sensys_lbp236dw_firmware
60 Canon i-sensys_lbp236dw
61 Canon i-sensys_lbp233dw_firmware
62 Canon i-sensys_lbp233dw
63 Canon imagerunner_1643if_ii_firmware
64 Canon imagerunner_1643if_ii
65 Canon imagerunner_1643i_ii_firmware
66 Canon imagerunner_1643i_ii
67 Canon i-sensys_x_1238if_ii_firmware
68 Canon i-sensys_x_1238if_ii
69 Canon i-sensys_x_1238i_ii_firmware
70 Canon i-sensys_x_1238i_ii
71 Canon i-sensys_x_1238p_ii_firmware
72 Canon i-sensys_x_1238p_ii
73 Canon i-sensys_x_1238pr_ii_firmware
74 Canon i-sensys_x_1238pr_ii
References to Advisories, Solutions, and Tools

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2025-2146 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2025-2146 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Jun. 03, 2025

    Action Type Old Value New Value
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-787
    Added CPE Configuration AND OR *cpe:2.3:o:canon:satera_mf656cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:satera_mf656cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:satera_mf654cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:satera_mf654cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:satera_mf551dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:satera_mf551dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:satera_mf457dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:satera_mf457dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf656cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf656cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf654cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf654cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf653cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf653cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf652cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf652cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_lbp633cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_lbp633cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_lbp632cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_lbp632cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf455dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf455dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf453dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf453dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf452dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf452dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_mf451dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_mf451dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_lbp237dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_lbp237dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_lbp236dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_lbp236dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_x_mf1238_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_x_mf1238_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_x_mf1643i_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_x_mf1643i_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_x_mf1643if_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_x_mf1643if_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imageclass_x_lbp1238_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imageclass_x_lbp1238_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_mf657cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_mf657cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_mf655cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_mf655cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_mf651cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_mf651cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_lbp633cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_lbp633cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_lbp631cdw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_lbp631cdw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_mf553dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_mf553dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_mf552dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_mf552dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_mf455dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_mf455dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_mf453dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_mf453dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_lbp236dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_lbp236dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_lbp233dw_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_lbp233dw:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imagerunner_1643if_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imagerunner_1643if_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:imagerunner_1643i_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:imagerunner_1643i_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_x_1238if_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_x_1238if_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_x_1238i_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_x_1238i_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_x_1238p_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_x_1238p_ii:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:canon:i-sensys_x_1238pr_ii_firmware:*:*:*:*:*:*:*:* versions up to (including) 05.07 OR cpe:2.3:h:canon:i-sensys_x_1238pr_ii:-:*:*:*:*:*:*:*
    Added Reference Type Canon Inc.: https://canon.jp/support/support-info/250127vulnerability-response Types: Vendor Advisory
    Added Reference Type Canon Inc.: https://psirt.canon/advisory-information/cp2025-001/ Types: Vendor Advisory
    Added Reference Type Canon Inc.: https://www.canon-europe.com/support/product-security/#news Types: Vendor Advisory
    Added Reference Type Canon Inc.: https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers Types: Vendor Advisory
  • New CVE Received by f98c90f0-e9bd-4fa7-911b-51993f3571fd

    May. 26, 2025

    Action Type Old Value New Value
    Added Description Buffer overflow in WebService Authentication processing of Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera MF656Cdw/Satera MF654Cdw/Satera MF551dw/Satera MF457dw firmware v05.07 and earlier sold in Japan. Color imageCLASS MF656Cdw/Color imageCLASS MF654Cdw/Color imageCLASS MF653Cdw/Color imageCLASS MF652Cdw/Color imageCLASS LBP633Cdw/Color imageCLASS LBP632Cdw/imageCLASS MF455dw/imageCLASS MF453dw/imageCLASS MF452dw/imageCLASS MF451dw/imageCLASS LBP237dw/imageCLASS LBP236dw/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II/imageCLASS X LBP1238 II firmware v05.07 and earlier sold in US. i-SENSYS MF657Cdw/i-SENSYS MF655Cdw/i-SENSYS MF651Cdw/i-SENSYS LBP633Cdw/i-SENSYS LBP631Cdw/i-SENSYS MF553dw/i-SENSYS MF552dw/i-SENSYS MF455dw/i-SENSYS MF453dw/i-SENSYS LBP236dw/i-SENSYS LBP233dw/imageRUNNER 1643iF II/imageRUNNER 1643i II/i-SENSYS X 1238iF II/i-SENSYS X 1238i II/i-SENSYS X 1238P II/i-SENSYS X 1238Pr II firmware v05.07 and earlier sold in Europe.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-787
    Added Reference https://canon.jp/support/support-info/250127vulnerability-response
    Added Reference https://psirt.canon/advisory-information/cp2025-001/
    Added Reference https://www.canon-europe.com/support/product-security/#news
    Added Reference https://www.usa.canon.com/support/canon-product-advisories/service-notice-regarding-vulnerability-measure-against-buffer-overflow-for-laser-printers-and-small-office-multifunctional-printers
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2025-2146 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2025-2146 weaknesses.

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
© cvefeed.io
Latest DB Update: Jul. 14, 2025 13:06