CVE-2025-9904 is an unallocated memory access vulnerability affecting various Canon Generic Plus and UFRII/CARPS2/LIPS/LIPSLX/PS Printer Drivers and the Generic FAX Driver during print processing. Rated Medium (CVSS 5.3), this network-based vulnerability requires no user interaction and has a low impact, primarily leading to a denial of service (availability loss). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Canon Inc. | CARPS2 Printer Driver | 31.05 and earlierCNA affecteddefault unaffected | |
| Canon Inc. | Generic FAX Driver | 10.67 and earlierCNA affecteddefault unaffected | |
| Canon Inc. | Generic Plus LIPS4 Printer Driver | 3.30 and earlierCNA affecteddefault unaffected | |
| Canon Inc. | Generic Plus LIPSLX Printer Driver | 3.30 and earlierCNA affecteddefault unaffected | |
| Canon Inc. | Generic Plus PCL6 Printer Driver | 3.30 and earlierCNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.