CVE-2023-26068

CRITICAL

Lexmark Device Embedded Web Server RCE

Title source: metasploit
STIX 2.1

Description

Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 2 of 4).

Scores

CVSS v3 9.8
EPSS 0.1163
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-20
Status published
Products (26)
lexmark/cslbl_firmware < cslbl.081.232
lexmark/cslbn_firmware < cslbn.081.232
lexmark/csnzj_firmware < csnzj.081.232
lexmark/cstat_firmware < cstat.081.233
lexmark/cstmh_firmware < cstmh.081.233
lexmark/cstpc_firmware < cstpc.081.232
lexmark/cxlbl_firmware < cxlbl.081.232
lexmark/cxlbn_firmware < cxlbn.081.232
lexmark/cxnzj_firmware < cxnzj.081.232
lexmark/cxtat_firmware < cxtat.081.233
... and 16 more
Published Apr 10, 2023
Tracked Since Feb 18, 2026