CVE-2025-2146 describes a critical buffer overflow vulnerability in the WebService Authentication processing of various Canon Small Office Multifunction and Laser Printers, including specific models sold in Japan, US, and Europe with firmware v05.07 and earlier. This flaw, rated 9.8 CVSS (CRITICAL), allows an unauthenticated attacker on the network segment to trigger device unresponsiveness or execute arbitrary code with high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, its high severity and network-based attack vector warrant immediate attention. The vulnerability is categorized as CWE-787 (Out-of-bounds Write).
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 05.07CPE matchmatch criteria | cpe:2.3:o:canon:satera_mf656cdw_firmware:*:*:*:*:*:*:*:* | ||
<= 05.07CPE matchmatch criteria | cpe:2.3:o:canon:satera_mf654cdw_firmware:*:*:*:*:*:*:*:* | ||
<= 05.07CPE matchmatch criteria | cpe:2.3:o:canon:satera_mf551dw_firmware:*:*:*:*:*:*:*:* | ||
<= 05.07CPE matchmatch criteria | cpe:2.3:o:canon:satera_mf457dw_firmware:*:*:*:*:*:*:*:* | ||
<= 05.07CPE matchmatch criteria | cpe:2.3:o:canon:imageclass_mf656cdw_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.