CVE-2023-25954 is an improper intent handling vulnerability affecting KYOCERA, UTAX/TA, and Olivetti Mobile Print Android applications versions 3.2.0.230119 and earlier. A malicious app installed on a user's device can exploit this to force the vulnerable print app to download malicious files or applications without user notification. Rated Medium severity (CVSS 5.5), this vulnerability requires user interaction (installing a malicious app) and has a high impact on integrity, as it can lead to unauthorized file downloads. There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though it has received some media coverage and community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.2.0.230119CPE matchmatch criteria | cpe:2.3:a:kyocera:mobile_print:*:*:*:*:*:android:*:* | ||
<= 3.2.0.230119CPE matchmatch criteria | cpe:2.3:a:triumph-adler:mobile_print:*:*:*:*:*:android:*:* | ||
<= 3.2.0.230119CPE matchmatch criteria | cpe:2.3:a:olivetti:mobile_print:*:*:*:*:*:android:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.