CVE-2025-14237 is a critical buffer overflow vulnerability (CVSS 9.8) affecting specific Canon Small Office Multifunction and Laser Printers, including models in the Satera, Color imageCLASS, and i-SENSYS series with firmware v06.02 and earlier. An unauthenticated attacker on the same network segment can exploit this flaw during XPS font parse processing to render the device unresponsive or execute arbitrary code. While no public exploit code or active exploitation has been observed, the vulnerability has garnered some community discussion, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 06.02CPE matchmatch criteria | cpe:2.3:o:canon:mf455dw_firmware:*:*:*:*:*:*:*:* | ||
<= 06.02CPE matchmatch criteria | cpe:2.3:o:canon:mf453dw_firmware:*:*:*:*:*:*:*:* | ||
<= 06.02CPE matchmatch criteria | cpe:2.3:o:canon:mf452dw_firmware:*:*:*:*:*:*:*:* | ||
<= 06.02CPE matchmatch criteria | cpe:2.3:o:canon:mf451dw_firmware:*:*:*:*:*:*:*:* | ||
<= 06.02CPE matchmatch criteria | cpe:2.3:o:canon:mf654cdw_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.