← Back to CVE List
CVE-2025-14237NVD
Vulnerability Summary
Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
CVSS v4.0 Base Metrics — Score 9.3 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)High
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Canon Mf455dw Firmware <= 06.02
- Canon Mf453dw Firmware <= 06.02
- Canon Mf452dw Firmware <= 06.02
- Canon Mf451dw Firmware <= 06.02
- Canon Mf654cdw Firmware <= 06.02
- Canon Mf656cdw Firmware <= 06.02
- Canon Mf653cdw Firmware <= 06.02
- Canon Mf652cw Firmware <= 06.02
- Canon Mf1238 Ii Firmware <= 06.02
- Canon Mf1643if Ii Firmware <= 06.02
- Canon Mf1643i Ii Firmware <= 06.02
- Canon Lbp237dw Firmware <= 06.02
- Canon Lbp236dw Firmware <= 06.02
- Canon Lbp633cdw Firmware <= 06.02
- Canon Lbp632cdw Firmware <= 06.02
- Canon Lbp1238 Ii Firmware <= 06.02
Not provided by NVD for this CVE.
External References
- https://canon.jp/support/support-info/260115vulnerability-response
- https://psirt.canon/advisory-information/cp2026-001/
- https://www.canon-europe.com/support/product-security/
- https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Remediation-Measure-Against-Potential-Buffer-Overflow-Vulnerability-in-Laser-Printers-and-Small-Office-Multifunctional-Printers